Vulnerabilities > CVE-2007-2268 - Unspecified vulnerability in Swsoft Plesk 7.6.1/8.1.0/8.1.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Exploit-Db
description | Plesk 8.1.1 Login.PHP3 Directory Traversal Vulnerability. CVE-2007-2268. Webapps exploit for php platform |
id | EDB-ID:29898 |
last seen | 2016-02-03 |
modified | 2007-04-25 |
published | 2007-04-25 |
reporter | anonymous |
source | https://www.exploit-db.com/download/29898/ |
title | plesk <= 8.1.1 login.php3 - Directory Traversal Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | PLESK_LOCALE_ID_TRAVERSAL.NASL |
description | The remote host is running Plesk, a control panel used to administer and manage websites. The version of Plesk installed on the remote host fails to sanitize user-supplied input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25090 |
published | 2007-04-27 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25090 |
title | Plesk Multiple Script locale_id Parameter Traversal Arbitrary File Access |
References
- http://forum.swsoft.com/showthread.php?s=&postid=172761#post172761
- http://forum.swsoft.com/showthread.php?s=&postid=172761#post172761
- http://kb.swsoft.com/en/1798
- http://kb.swsoft.com/en/1798
- http://secunia.com/advisories/25036
- http://secunia.com/advisories/25036
- http://www.osvdb.org/34081
- http://www.osvdb.org/34081
- http://www.osvdb.org/34082
- http://www.osvdb.org/34082
- http://www.securityfocus.com/bid/23639
- http://www.securityfocus.com/bid/23639
- http://www.vupen.com/english/advisories/2007/1588
- http://www.vupen.com/english/advisories/2007/1588