← Back

CVE-2011-4851

nvd nist
Published: Dec 16, 2011Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in server/google-tools/ and certain other files.

Affected (1)

1 product
Parallels Plesk Panel
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 10.4.4_build20111103.18
Running on/withPlatform Versions
Microsoft
Windows 2003 Server
All versions
Microsoft
Windows Server 2008
All versions

Related CWEs

Timeline

No history available yet.