NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
11181  CVE-2011-4851  The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in server/google-tools/ and certain other files.    9.3  High  2017-01-07  2012-02-16  View
11182  CVE-2011-4852  The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates web pages containing external links in response to GET requests with query strings for enterprise/mobile-monitor/ and certain other files, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue.    4.3  Medium  2017-01-07  2012-02-16  View
11183  CVE-2011-4853  The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes an RFC 1918 IP address within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by smb/user/list-data/items-per-page/ and certain other files.    4.3  Medium  2017-01-07  2012-02-16  View
11184  CVE-2011-4854  The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corresponding Content-Type data in HTML META elements, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving the get_enabled_product_icon program. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.    9.3  High  2017-01-07  2012-02-16  View
11185  CVE-2011-4855  The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Content-Type header"s charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/customer-service-plan/list/reset-search/true/ and certain other files. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.    9.3  High  2017-01-07  2012-02-16  View

Page 2237 of 17672, showing 5 records out of 88360 total, starting on record 11181, ending on 11185

Actions