Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by login_up.php3 and certain other files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Parallels Plesk Panel设计错误漏洞
Vulnerability Description
Parallels Plesk Panel 10.2.0_build1011110331.18版本中存在漏洞,其服务器管理面板在cookie的Set-Cookie头中不包含HTTPOnly标志。远程攻击者更易于借助对该cookie的脚本访问获取潜在地敏感信息,该漏洞已在login_up.php3和某些其他文件中被证实。
CVSS Information
N/A
Vulnerability Type
N/A