Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2011-4777
Cross-site scripting (XSS) vulnerability in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to inject arbitrary web script or HTML via the login parameter to preferences.html.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.002
EPSS Ranking
45.4%
CVSS Severity
CVSS v2 Score
4.3
References
http://xss.cx/kb/parallels/xss-parallelspleskpanel.v10.4.4_build20111103.18-os_windows-2003-2008-reflected-cross-site-scripting-cwe79-capec86-javascript-injection-example-poc-report.html
http://xss.cx/kb/parallels/xss-parallelspleskpanel.v10.4.4_build20111103.18-os_windows-2003-2008-reflected-cross-site-scripting-cwe79-capec86-javascript-injection-example-poc-report.html
Products affected by CVE-2011-4777
Parallels
»
Parallels Plesk Panel
»
Version:
10.4.4_build20111103.18
cpe:2.3:a:parallels:parallels_plesk_panel:10.4.4_build20111103.18
Microsoft
»
Windows 2003 Server
»
Version:
N/A
cpe:2.3:o:microsoft:windows_2003_server:-
Microsoft
»
Windows Server 2008
»
Version:
N/A
cpe:2.3:o:microsoft:windows_server_2008:-
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved