Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jxp6-mf7j-ffh8

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error) or possibly have unspecified other impact via a crafted cookie, as demonstrated by cookies to client@1/domain@1/hosting/file-manager/ and certain other files.

Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error) or possibly have unspecified other impact via a crafted cookie, as demonstrated by cookies to client@1/domain@1/hosting/file-manager/ and certain other files.

EPSS

Процентиль: 83%
0.01863
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
около 14 лет назад

Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error) or possibly have unspecified other impact via a crafted cookie, as demonstrated by cookies to client@1/domain@1/hosting/file-manager/ and certain other files.

EPSS

Процентиль: 83%
0.01863
Низкий

Дефекты

CWE-20