NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 11181 | CVE-2011-4851 | The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in server/google-tools/ and certain other files. | 2 | 9.3 | High | 2017-01-07 | 2012-02-16 | View | |
| 11182 | CVE-2011-4852 | The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates web pages containing external links in response to GET requests with query strings for enterprise/mobile-monitor/ and certain other files, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue. | 2 | 4.3 | Medium | 2017-01-07 | 2012-02-16 | View | |
| 11183 | CVE-2011-4853 | The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes an RFC 1918 IP address within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by smb/user/list-data/items-per-page/ and certain other files. | 2 | 4.3 | Medium | 2017-01-07 | 2012-02-16 | View | |
| 11184 | CVE-2011-4854 | The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corresponding Content-Type data in HTML META elements, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving the get_enabled_product_icon program. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue. | 2 | 9.3 | High | 2017-01-07 | 2012-02-16 | View | |
| 11185 | CVE-2011-4855 | The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Content-Type header"s charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/customer-service-plan/list/reset-search/true/ and certain other files. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue. | 2 | 9.3 | High | 2017-01-07 | 2012-02-16 | View |
Page 2237 of 17672, showing 5 records out of 88360 total, starting on record 11181, ending on 11185