CVE Vulnerabilities

CVE-2011-4749

Published: Dec 16, 2011 | Modified: Apr 22, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms on certain pages under admin/index.php/default.

Affected Software

Name Vendor Start Version End Version
Parallels_plesk_panel Parallels 10.3.1_build1013110726.09 (including) 10.3.1_build1013110726.09 (including)

References