Lucene search

K
cveMitreCVE-2011-4736
HistoryDec 16, 2011 - 11:55 a.m.

CVE-2011-4736

2011-12-1611:55:09
CWE-310
mitre
web.nvd.nist.gov
19
cve-2011-4736
control panel
parallels plesk panel
network sniffing
http
security vulnerability

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

61.1%

The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 receives cleartext password input over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by forms in login_up.php3 and certain other files.

Affected configurations

Nvd
Node
parallelsparallels_plesk_panelMatch10.2.0_build20110407.20
AND
microsoftwindows
OR
redhatenterprise_linuxMatch6.0
VendorProductVersionCPE
parallelsparallels_plesk_panel10.2.0_build20110407.20cpe:2.3:a:parallels:parallels_plesk_panel:10.2.0_build20110407.20:*:*:*:*:*:*:*
microsoftwindows*cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
redhatenterprise_linux6.0cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

61.1%

Related for CVE-2011-4736