Vulnerabilities > Parallels > High

DATE CVE VULNERABILITY TITLE RISK
2011-12-16 CVE-2011-4734 SQL Injection vulnerability in Parallels Plesk Panel 10.2.0Build20110407.20
Multiple SQL injection vulnerabilities in the Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by file-manager/ and certain other files.
network
low complexity
parallels microsoft redhat CWE-89
7.5
2011-12-16 CVE-2011-4725 SQL Injection vulnerability in Parallels Plesk Panel 10.2.0Build1011110331.18
Multiple SQL injection vulnerabilities in the Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by login_up.php3 and certain other files.
network
low complexity
parallels microsoft redhat CWE-89
7.5
2007-03-02 CVE-2007-1222 Local Security vulnerability in Parallels Desktop for Mac OS X
Parallels Desktop for Mac before 20070216 implements Drag and Drop by sharing the entire host filesystem as the .psf share, which allows local users of the guest operating system to write arbitrary files to the host filesystem, and execute arbitrary code via launchd by writing a plist file to a LaunchAgents directory.
local
low complexity
apple parallels
7.2