<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Plesk</title>
  <link>https://cvedaily.com/pages/tags/plesk.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/plesk.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Plesk</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:39 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-44962 – Plesk contains an XPath injection vulnerability in the APS Application Catalog s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44962</guid>
    <pubDate>Fri, 29 May 2026 16:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44962</strong></p>
  <p>Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-643</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65518 – Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65518</guid>
    <pubDate>Thu, 08 Jan 2026 19:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65518</strong></p>
  <p>Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service unavailable to legitimate users. An attacker can exploit this issue remotely without authentication,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66430 – Plesk 18.0 has Incorrect Access Control.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66430</guid>
    <pubDate>Fri, 12 Dec 2025 16:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66430</strong></p>
  <p>Plesk 18.0 has Incorrect Access Control.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66431 – WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66431</guid>
    <pubDate>Wed, 03 Dec 2025 17:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66431</strong></p>
  <p>WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitrary code as root via domain creation. The attacker needs "Create and manage sites" with "Domains management" and "Subdomains management."</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54336 – In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54336</guid>
    <pubDate>Tue, 19 Aug 2025 14:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54336</strong></p>
  <p>In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-697</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-49618 – In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49618</guid>
    <pubDate>Thu, 03 Jul 2025 13:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-49618</strong></p>
  <p>In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-402</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24832 – Arbitrary file overwrite during home directory recovery due to improper symbolic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24832</guid>
    <pubDate>Thu, 27 Feb 2025 23:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24832</strong></p>
  <p>Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.7.615.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34014 – Arbitrary file overwrite during recovery due to improper symbolic link handling...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34014</guid>
    <pubDate>Mon, 11 Nov 2024 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34014</strong></p>
  <p>Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.6.599, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.2.181.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-8767 – Sensitive data disclosure and manipulation due to unnecessary privileges assignm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8767</guid>
    <pubDate>Tue, 17 Sep 2024 09:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-8767</strong></p>
  <p>Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-4931 – Uncontrolled search path element vulnerability in Plesk Installer affects versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4931</guid>
    <pubDate>Mon, 27 Nov 2023 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-4931</strong></p>
  <p>Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43784 – Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43784</guid>
    <pubDate>Fri, 22 Sep 2023 06:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43784</strong></p>
  <p>Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0829 – Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0829</guid>
    <pubDate>Wed, 20 Sep 2023 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0829</strong></p>
  <p>Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-24044 – A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24044</guid>
    <pubDate>Sun, 22 Jan 2023 03:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-24044</strong></p>
  <p>A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names to access the panel is an intended feature."</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-45130 – Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45130</guid>
    <pubDate>Thu, 10 Nov 2022 06:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-45130</strong></p>
  <p>Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so that versions are identified by names ("Obsidian"), not numbers.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45008 – Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45008</guid>
    <pubDate>Mon, 21 Feb 2022 12:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45008</strong></p>
  <p>Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-45007 – Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45007</guid>
    <pubDate>Sun, 20 Feb 2022 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-45007</strong></p>
  <p>Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45007">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-35976 – The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Lin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35976</guid>
    <pubDate>Fri, 10 Sep 2021 12:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-35976</strong></p>
  <p>The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /plesk-site-preview/ PATH, aka PFSI-62467. The attacker could execute JavaScript code in the victim's browser by using the link to preview sites hosted on the server. Authentication is not required to exploit the vulnerability.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-11584 – A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11584</guid>
    <pubDate>Mon, 03 Aug 2020 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-11584</strong></p>
  <p>A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-11583 – A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11583</guid>
    <pubDate>Mon, 03 Aug 2020 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-11583</strong></p>
  <p>A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-18793 – Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18793</guid>
    <pubDate>Wed, 13 Nov 2019 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-18793</strong></p>
  <p>Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2018-5693 – The LinuxMagic MagicSpam extension before 2.0.14-1 for Plesk allows local users ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-5693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-5693</guid>
    <pubDate>Sun, 14 Jan 2018 04:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2018-5693</strong></p>
  <p>The LinuxMagic MagicSpam extension before 2.0.14-1 for Plesk allows local users to discover mailbox names by reading /var/log/magicspam/mslog.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-4878 – The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4878</guid>
    <pubDate>Thu, 18 Jul 2013 16:51:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-4878</strong></p>
  <p>The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-0133 – Untrusted search path vulnerability in /usr/local/psa/admin/sbin/wrapper in Para...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0133</guid>
    <pubDate>Thu, 18 Apr 2013 18:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-0133</strong></p>
  <p>Untrusted search path vulnerability in /usr/local/psa/admin/sbin/wrapper in Parallels Plesk Panel 11.0.9 allows local users to gain privileges via a crafted PATH environment variable.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-0132 – The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0132</guid>
    <pubDate>Thu, 18 Apr 2013 18:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-0132</strong></p>
  <p>The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remote attackers to execute arbitrary PHP code via a request containing crafted environment variables.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-1557 – SQL injection vulnerability in admin/plib/api-rpc/Agent.php in Parallels Plesk P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1557</guid>
    <pubDate>Mon, 12 Mar 2012 19:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-1557</strong></p>
  <p>SQL injection vulnerability in admin/plib/api-rpc/Agent.php in Parallels Plesk Panel 7.x and 8.x before 8.6 MU#2, 9.x before 9.5 MU#11, 10.0.x before MU#13, 10.1.x before MU#22, 10.2.x before MU#16, and 10.3.x before MU#5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in March 2012.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4856 – The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4856</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4856</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/health/parameters and certain other files.  NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4855 – The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4855</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4855</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/customer-service-plan/list/reset-search/true/ and certain other files.  NOTE: it is possible that only clients, not the Plesk product, co…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4854 – The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4854</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4854</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corresponding Content-Type data in HTML META elements, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving the get_enabled_product_icon program.  NOTE: it is possible that only clients, not the Plesk product, co…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4853 – The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes an R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4853</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4853</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes an RFC 1918 IP address within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by smb/user/list-data/items-per-page/ and certain other files.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4852 – The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates web...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4852</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4852</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates web pages containing external links in response to GET requests with query strings for enterprise/mobile-monitor/ and certain other files, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer lea…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4851 – The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4851</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4851</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4851</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in server/google-tools/ and certain other files.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4851">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4850 – The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not incl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4850</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4850</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by help.php and certain other files.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4849 – The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not set ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4849</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4849</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session, as demonstrated by cookies used by help.php and certain other files.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4848 – The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes a su...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4848</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4848</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by password handling in certain files under client@1/domain@1/backup/local-repository/.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-4847 – SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4847</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-4847</strong></p>
  <p>SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to execute arbitrary SQL commands via a certificateslist cookie to notification@/.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4777 – Cross-site scripting (XSS) vulnerability in the Site Editor (aka SiteBuilder) fe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4777</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4777</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to inject arbitrary web script or HTML via the login parameter to preferences.html.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4776 – Multiple cross-site scripting (XSS) vulnerabilities in the Control Panel in Para...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4776</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4776</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by admin/update/settings/ and certain other files.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4768 – The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Pane...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4768</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4768</strong></p>
  <p>The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving Wizard/Edit/Modules/Image and certain other files.  NOTE: it is possible that only clients, not the Plesk product, could…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4767 – The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Pane...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4767</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4767</strong></p>
  <p>The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive information by reading a page, as demonstrated by js/Wizard/Status.js and certain other files.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4766 – The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Pane...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4766</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4766</strong></p>
  <p>The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allows remote attackers to obtain ASP source code via a direct request to wysiwyg/fckconfig.js.  NOTE: CVE disputes this issue because ASP is only used in a JavaScript comment</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4765 – The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Pane...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4765</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4765</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4765</strong></p>
  <p>The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by Wizard/Edit/Modules/ImageGallery/MultiImagesUpload and certain other files.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4765">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4764 – Multiple cross-site scripting (XSS) vulnerabilities in the Site Editor (aka Site...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4764</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4764</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by Wizard/Edit/Modules/Image and certain other files.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-4763 – Multiple SQL injection vulnerabilities in the Site Editor (aka SiteBuilder) feat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4763</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-4763</strong></p>
  <p>Multiple SQL injection vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by Wizard/Edit/Html and certain other files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4762 – Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4762</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4762</strong></p>
  <p>Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/app/top-categories-data/ and certain other files.  NOTE: it is possible that only clients, not the SmarterStats product, could be affected by this issue.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4761 – Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's char...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4761</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4761</strong></p>
  <p>Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving domains/sitebuilder_edit.php and certain other files.  NOTE: it is possible that only clients, not the SmarterStats product, could be affected by this issue.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4760 – Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4760</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4760</strong></p>
  <p>Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive information by reading a page, as demonstrated by smb/email-address/list and certain other files.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4759 – Parallels Plesk Small Business Panel 10.2.0 generates web pages containing exter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4759</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4759</strong></p>
  <p>Parallels Plesk Small Business Panel 10.2.0 generates web pages containing external links in response to GET requests with query strings for client@1/domain@1/hosting/file-manager/ and certain other files, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issu…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4758 – Parallels Plesk Small Business Panel 10.2.0 receives cleartext password input ov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4758</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4758</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4758</strong></p>
  <p>Parallels Plesk Small Business Panel 10.2.0 receives cleartext password input over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by forms in smb/auth and certain other files.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4758">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4757 – Parallels Plesk Small Business Panel 10.2.0 generates a password form field with...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4757</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4757</strong></p>
  <p>Parallels Plesk Small Business Panel 10.2.0 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in smb/auth and certain other files.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4756 – Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4756</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4756</strong></p>
  <p>Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by domains/sitebuilder_edit.php and certain other files.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4755 – Parallels Plesk Small Business Panel 10.2.0 does not properly validate string da...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4755</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4755</strong></p>
  <p>Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error) or possibly have unspecified other impact via a crafted cookie, as demonstrated by cookies to client@1/domain@1/hosting/file-manager/ and certain other files.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4754 – Multiple cross-site scripting (XSS) vulnerabilities in Parallels Plesk Small Bus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4754</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4754</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by smb/app/available/id/apscatalog/ and certain other files.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-4753 – Multiple SQL injection vulnerabilities in Parallels Plesk Small Business Panel 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4753</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-4753</strong></p>
  <p>Multiple SQL injection vulnerabilities in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by domains/sitebuilder_edit.php and certain other files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4749 – The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4749</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4749</strong></p>
  <p>The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms on certain pages under admin/index.php/default.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4748 – The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 has web p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4748</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4748</strong></p>
  <p>The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive information by reading a page, as demonstrated by js/ajax/core/ajax.inc.js and certain other files.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4747 – The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4747</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4747</strong></p>
  <p>The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not prevent the use of weak ciphers for SSL sessions, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a crafted CipherSuite list.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4747">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4746 – The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4746</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4746</strong></p>
  <p>The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not disable the SSL 2.0 protocol, which makes it easier for remote attackers to conduct spoofing attacks by leveraging protocol weaknesses.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4745 – Multiple cross-site scripting (XSS) vulnerabilities in the billing system for Pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4745</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4745</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4745</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in the billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by admin/index.php/default and certain other files.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4745">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4744 – The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 sends incorr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4744</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4744</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/admin-home/featured-applications/ and certain other files.  NOTE: it is possible that only clients, not the Plesk product, could be affected by this is…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4743 – The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 omits the Co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4743</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4743</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/user/create and certain other files.  NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4742 – The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 has web page...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4742</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4742</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4742</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive information by reading a page, as demonstrated by smb/user/list and certain other files.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4742">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4741 – The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4741</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4741</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a database connection string within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by client@2/domain@1/hosting/aspdotnet/.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4740 – The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates we...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4740</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4740</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates web pages containing external links in response to GET requests with query strings for smb/app/search-data/catalogId/marketplace and certain other files, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-do…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4739 – The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4739</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4739</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in smb/my-profile and certain other files.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4738 – The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 does not inc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4738</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4738</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by get_password.php and certain other files.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4737 – The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4737</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4737</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by password handling in client@2/domain@1/odbc/dsn@1/properties/.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4736 – The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 receives cle...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4736</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4736</strong></p>
  <p>The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 receives cleartext password input over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by forms in login_up.php3 and certain other files.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4735 – Multiple cross-site scripting (XSS) vulnerabilities in the Control Panel in Para...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4735</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4735</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in the Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by smb/user/create and certain other files.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-4734 – Multiple SQL injection vulnerabilities in the Control Panel in Parallels Plesk P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4734</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-4734</strong></p>
  <p>Multiple SQL injection vulnerabilities in the Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by file-manager/ and certain other files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4733 – The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4733</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4733</strong></p>
  <p>The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/admin-home/disable-featured-applications-promo and certain other files.  NOTE: it is possible that only clients, not the Plesk product,…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4732 – The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4732</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4732</strong></p>
  <p>The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving account/power-mode-logout and certain other files.  NOTE: it is possible that only clients, not the Plesk product, could be aff…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4731 – The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4731</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4731</strong></p>
  <p>The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 includes an RFC 1918 IP address within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by admin/home/admin and certain other files.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4730 – The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4730</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4730</strong></p>
  <p>The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in admin/reseller/login-info/ and certain other files.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4729 – The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4729</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4729</strong></p>
  <p>The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by login_up.php3 and certain other files.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4728 – The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4728</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4728</strong></p>
  <p>The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session, as demonstrated by cookies used by login_up.php3 and certain other files.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4727 – The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4727</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4727</strong></p>
  <p>The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error) or possibly have unspecified other impact via a crafted REST URL parameter, as demonstrated by parameters to admin/ and certain other files.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4726 – Multiple cross-site scripting (XSS) vulnerabilities in the Server Administration...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4726</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4726</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in the Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by admin/health/ and certain other files.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-4725 – Multiple SQL injection vulnerabilities in the Server Administration Panel in Par...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4725</guid>
    <pubDate>Fri, 16 Dec 2011 11:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-4725</strong></p>
  <p>Multiple SQL injection vulnerabilities in the Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by login_up.php3 and certain other files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-6984 – Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6984</guid>
    <pubDate>Wed, 19 Aug 2009 05:24:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-6984</strong></p>
  <p>Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-3579 – Calacode @Mail 5.41 on Linux does not require administrative authentication for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3579</guid>
    <pubDate>Sun, 10 Aug 2008 21:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-3579</strong></p>
  <p>Calacode @Mail 5.41 on Linux does not require administrative authentication for build-plesk-upgrade.php, which allows remote attackers to obtain sensitive information by creating and downloading a backup archive of the entire @Mail directory tree.  NOTE: this can be leveraged for remote exploitation of CVE-2008-3395.  NOTE: the provenance of this information is unknown; the details are obtained s…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4892 – Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4892</guid>
    <pubDate>Fri, 14 Sep 2007 18:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4892</strong></p>
  <p>Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie to (1) login.php3 or (2) auth.php3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-2268 – Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-2268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-2268</guid>
    <pubDate>Wed, 25 Apr 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-2268</strong></p>
  <p>Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-2268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-2269 – Directory traversal vulnerability in top.php3 in SWsoft Plesk for Windows 8.1 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-2269</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-2269</guid>
    <pubDate>Wed, 25 Apr 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-2269</strong></p>
  <p>Directory traversal vulnerability in top.php3 in SWsoft Plesk for Windows 8.1 and 8.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-2269">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-6451 – Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and ea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6451</guid>
    <pubDate>Sun, 10 Dec 2006 21:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-6451</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) get_password.php or (2) login_up.php3.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-5028 – Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5028</guid>
    <pubDate>Wed, 27 Sep 2006 23:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-5028</strong></p>
  <p>Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directories via a ../ (dot dot slash) in the file parameter in a chdir action.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-3737 – Cross-site scripting (XSS) vulnerability in filemanager/filemanager.php in the c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-3737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-3737</guid>
    <pubDate>Fri, 21 Jul 2006 14:03:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-3737</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in filemanager/filemanager.php in the control panel in SWsoft Plesk 8.0 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the file parameter.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-3737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2004-2702 – Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-2702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-2702</guid>
    <pubDate>Fri, 31 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2004-2702</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter.  NOTE: this might be the same vector as CVE-2006-6451.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-2702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2001-1222 – Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP sourc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2001-1222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2001-1222</guid>
    <pubDate>Mon, 25 Mar 2002 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2001-1222</strong></p>
  <p>Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2001-1222">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
