<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Plesk (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/plesk.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/plesk-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Plesk (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:39 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-44962 – Plesk contains an XPath injection vulnerability in the APS Application Catalog s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44962</guid>
    <pubDate>Fri, 29 May 2026 16:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44962</strong></p>
  <p>Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-643</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65518 – Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65518</guid>
    <pubDate>Thu, 08 Jan 2026 19:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65518</strong></p>
  <p>Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service unavailable to legitimate users. An attacker can exploit this issue remotely without authentication,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66430 – Plesk 18.0 has Incorrect Access Control.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66430</guid>
    <pubDate>Fri, 12 Dec 2025 16:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66430</strong></p>
  <p>Plesk 18.0 has Incorrect Access Control.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66431 – WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66431</guid>
    <pubDate>Wed, 03 Dec 2025 17:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66431</strong></p>
  <p>WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitrary code as root via domain creation. The attacker needs "Create and manage sites" with "Domains management" and "Subdomains management."</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54336 – In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54336</guid>
    <pubDate>Tue, 19 Aug 2025 14:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54336</strong></p>
  <p>In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-697</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-8767 – Sensitive data disclosure and manipulation due to unnecessary privileges assignm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8767</guid>
    <pubDate>Tue, 17 Sep 2024 09:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-8767</strong></p>
  <p>Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43784 – Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43784</guid>
    <pubDate>Fri, 22 Sep 2023 06:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43784</strong></p>
  <p>Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0829 – Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0829</guid>
    <pubDate>Wed, 20 Sep 2023 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0829</strong></p>
  <p>Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45008 – Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45008</guid>
    <pubDate>Mon, 21 Feb 2022 12:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45008</strong></p>
  <p>Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-4878 – The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4878</guid>
    <pubDate>Thu, 18 Jul 2013 16:51:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-4878</strong></p>
  <p>The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-0133 – Untrusted search path vulnerability in /usr/local/psa/admin/sbin/wrapper in Para...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0133</guid>
    <pubDate>Thu, 18 Apr 2013 18:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-0133</strong></p>
  <p>Untrusted search path vulnerability in /usr/local/psa/admin/sbin/wrapper in Parallels Plesk Panel 11.0.9 allows local users to gain privileges via a crafted PATH environment variable.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-1557 – SQL injection vulnerability in admin/plib/api-rpc/Agent.php in Parallels Plesk P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1557</guid>
    <pubDate>Mon, 12 Mar 2012 19:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-1557</strong></p>
  <p>SQL injection vulnerability in admin/plib/api-rpc/Agent.php in Parallels Plesk Panel 7.x and 8.x before 8.6 MU#2, 9.x before 9.5 MU#11, 10.0.x before MU#13, 10.1.x before MU#22, 10.2.x before MU#16, and 10.3.x before MU#5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in March 2012.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4856 – The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4856</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4856</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/health/parameters and certain other files.  NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4855 – The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4855</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4855</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/customer-service-plan/list/reset-search/true/ and certain other files.  NOTE: it is possible that only clients, not the Plesk product, co…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4854 – The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4854</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4854</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corresponding Content-Type data in HTML META elements, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving the get_enabled_product_icon program.  NOTE: it is possible that only clients, not the Plesk product, co…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4851 – The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4851</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4851</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4851</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in server/google-tools/ and certain other files.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4851">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-4847 – SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4847</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-4847</strong></p>
  <p>SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to execute arbitrary SQL commands via a certificateslist cookie to notification@/.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4768 – The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Pane...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4768</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4768</strong></p>
  <p>The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving Wizard/Edit/Modules/Image and certain other files.  NOTE: it is possible that only clients, not the Plesk product, could…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-4763 – Multiple SQL injection vulnerabilities in the Site Editor (aka SiteBuilder) feat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4763</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-4763</strong></p>
  <p>Multiple SQL injection vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by Wizard/Edit/Html and certain other files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4762 – Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4762</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4762</strong></p>
  <p>Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/app/top-categories-data/ and certain other files.  NOTE: it is possible that only clients, not the SmarterStats product, could be affected by this issue.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4761 – Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's char...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4761</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4761</strong></p>
  <p>Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving domains/sitebuilder_edit.php and certain other files.  NOTE: it is possible that only clients, not the SmarterStats product, could be affected by this issue.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4757 – Parallels Plesk Small Business Panel 10.2.0 generates a password form field with...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4757</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4757</strong></p>
  <p>Parallels Plesk Small Business Panel 10.2.0 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in smb/auth and certain other files.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4755 – Parallels Plesk Small Business Panel 10.2.0 does not properly validate string da...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4755</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4755</strong></p>
  <p>Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error) or possibly have unspecified other impact via a crafted cookie, as demonstrated by cookies to client@1/domain@1/hosting/file-manager/ and certain other files.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-4753 – Multiple SQL injection vulnerabilities in Parallels Plesk Small Business Panel 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4753</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-4753</strong></p>
  <p>Multiple SQL injection vulnerabilities in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by domains/sitebuilder_edit.php and certain other files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4749 – The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4749</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4749</strong></p>
  <p>The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms on certain pages under admin/index.php/default.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4744 – The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 sends incorr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4744</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4744</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/admin-home/featured-applications/ and certain other files.  NOTE: it is possible that only clients, not the Plesk product, could be affected by this is…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4743 – The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 omits the Co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4743</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4743</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/user/create and certain other files.  NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4739 – The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4739</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4739</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in smb/my-profile and certain other files.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-4734 – Multiple SQL injection vulnerabilities in the Control Panel in Parallels Plesk P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4734</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-4734</strong></p>
  <p>Multiple SQL injection vulnerabilities in the Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by file-manager/ and certain other files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4733 – The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4733</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4733</strong></p>
  <p>The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/admin-home/disable-featured-applications-promo and certain other files.  NOTE: it is possible that only clients, not the Plesk product,…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4732 – The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4732</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4732</strong></p>
  <p>The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving account/power-mode-logout and certain other files.  NOTE: it is possible that only clients, not the Plesk product, could be aff…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4730 – The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4730</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4730</strong></p>
  <p>The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in admin/reseller/login-info/ and certain other files.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4727 – The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4727</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4727</strong></p>
  <p>The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error) or possibly have unspecified other impact via a crafted REST URL parameter, as demonstrated by parameters to admin/ and certain other files.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-4725 – Multiple SQL injection vulnerabilities in the Server Administration Panel in Par...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4725</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-4725</strong></p>
  <p>Multiple SQL injection vulnerabilities in the Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by login_up.php3 and certain other files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-3579 – Calacode @Mail 5.41 on Linux does not require administrative authentication for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3579</guid>
    <pubDate>Sun, 10 Aug 2008 21:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-3579</strong></p>
  <p>Calacode @Mail 5.41 on Linux does not require administrative authentication for build-plesk-upgrade.php, which allows remote attackers to obtain sensitive information by creating and downloading a backup archive of the entire @Mail directory tree.  NOTE: this can be leveraged for remote exploitation of CVE-2008-3395.  NOTE: the provenance of this information is unknown; the details are obtained s…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4892 – Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4892</guid>
    <pubDate>Fri, 14 Sep 2007 18:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4892</strong></p>
  <p>Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie to (1) login.php3 or (2) auth.php3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4892">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
