MEDIUM · 4.3

CVE-2011-4765

The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attack...

Vulnerability Description

The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by Wizard/Edit/Modules/ImageGallery/MultiImagesUpload and certain other files.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ParallelsParallels Plesk Small Business Panel10.2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-4765?

CVE-2011-4765 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attack...

How severe is CVE-2011-4765?

CVE-2011-4765 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-4765?

Check the references section above for vendor advisories and patch information. Affected products include: Parallels Parallels Plesk Small Business Panel.