Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by domains/sitebuilder_edit.php and certain other files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Parallels Plesk Small Business Panel信息泄露漏洞
Vulnerability Description
Parallels Plesk Small Business Panel 10.2.0版本中存在漏洞,其在cookie的Set-Cookie头中不包含HTTPOnly标志。远程攻击者更易于借助对该cookie的脚本访问获取潜在地敏感信息,正如domains/sitebuilder_edit.php和某些其他文件中使用的cookies证明的。
CVSS Information
N/A
Vulnerability Type
N/A