CVE-2011-4758
Parallels Plesk Small Business Panel 10.2.0 - Cleartext Password Transmission via HTTP
Title source: llmDescription
Parallels Plesk Small Business Panel 10.2.0 receives cleartext password input over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by forms in smb/auth and certain other files.
References (2)
Core 2
Core References
Various Sources x_refsource_misc
http://xss.cx/examples/plesk-reports/plesk-10.2.0.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72210
Scores
EPSS
0.0116
EPSS Percentile
63.6%
Details
CWE
CWE-310
Status
published
Products (1)
parallels/parallels_plesk_small_business_panel
10.2.0
Published
Dec 16, 2011
Tracked Since
Feb 18, 2026