Plesk Sitebuilder Multiple Security Vulnerabilities
BID:43386
Info
Plesk Sitebuilder Multiple Security Vulnerabilities
| Bugtraq ID: | 43386 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2010 12:00AM |
| Updated: | Sep 07 2010 12:00AM |
| Credit: | Sid3^effects and Reported by the vendor. |
| Vulnerable: | |
| Not Vulnerable: |
Agrinsoft Agrin All DVD Ripper 4.0 |
Discussion
Plesk Sitebuilder Multiple Security Vulnerabilities
Plesk Sitebuilder is prone to multiple security vulnerabilities, including an HTML-injection issue and multiple unspecified issues.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. The impact of the unspecified issues is currently unknown.
Versions prior to Plesk Sitebuilder 4.5.8 are vulnerable.
Plesk Sitebuilder is prone to multiple security vulnerabilities, including an HTML-injection issue and multiple unspecified issues.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. The impact of the unspecified issues is currently unknown.
Versions prior to Plesk Sitebuilder 4.5.8 are vulnerable.
Exploit / POC
Plesk Sitebuilder Multiple Security Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
Plesk Sitebuilder Multiple Security Vulnerabilities
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
Plesk Sitebuilder Multiple Security Vulnerabilities
References:
References:
- Parallels Plesk Sitebuilder 4.5.8 for Linux/Unix Release Notes (Parallels)
- Product Homepage (Parallels)