← Back

CVE-2011-4749

nvd nist
Published: Dec 16, 2011Modified: Apr 29, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms on certain pages under admin/index.php/default.

Affected (1)

1 product
Parallels Plesk Panel
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 10.3.1_build1013110726.09
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 6.0

Related CWEs

Timeline

No history available yet.