CVE-2011-4737 describes an information disclosure vulnerability in Parallels Plesk Panel 10.2.0, where the Control Panel inadvertently includes submitted passwords within HTTP response bodies. This flaw allows remote attackers to capture sensitive information, specifically passwords, by sniffing network traffic. With a CVSS score of 5.0 (medium severity), this vulnerability is easily exploitable over the network with low complexity, potentially leading to unauthorized access to user credentials. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.2.0_build20110407.20CPE matchmatch criteria | cpe:2.3:a:parallels:parallels_plesk_panel:10.2.0_build20110407.20:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.