Vulnerabilities > CVE-2011-4739 - Credentials Management vulnerability in Parallels Plesk Panel 10.2.0Build20110407.20

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in smb/my-profile and certain other files.

Vulnerable Configurations

Part Description Count
Application
Parallels
1
OS
Microsoft
1
OS
Redhat
1

Common Weakness Enumeration (CWE)