CVE-2011-4763
Parallels Plesk Small Business Panel 10.2.0 - SQL Injection via Site Editor Input
Title source: llmDescription
Multiple SQL injection vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by Wizard/Edit/Html and certain other files.
References (2)
Core 2
Core References
Various Sources x_refsource_misc
http://xss.cx/examples/plesk-reports/plesk-10.2.0-site-editor.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72215
Scores
EPSS
0.0112
EPSS Percentile
62.7%
Details
CWE
CWE-89
Status
published
Products (1)
parallels/parallels_plesk_small_business_panel
10.2.0
Published
Dec 16, 2011
Tracked Since
Feb 18, 2026