Vulnerabilities > CVE-2007-2268 - Directory Traversal vulnerability in Swsoft Plesk 7.6.1/8.1.0/8.1.1

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
swsoft
nessus
exploit available

Summary

Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.

Vulnerable Configurations

Part Description Count
Application
Swsoft
3

Exploit-Db

descriptionPlesk 8.1.1 Login.PHP3 Directory Traversal Vulnerability. CVE-2007-2268. Webapps exploit for php platform
idEDB-ID:29898
last seen2016-02-03
modified2007-04-25
published2007-04-25
reporteranonymous
sourcehttps://www.exploit-db.com/download/29898/
titleplesk <= 8.1.1 login.php3 - Directory Traversal Vulnerability

Nessus

NASL familyCGI abuses
NASL idPLESK_LOCALE_ID_TRAVERSAL.NASL
descriptionThe remote host is running Plesk, a control panel used to administer and manage websites. The version of Plesk installed on the remote host fails to sanitize user-supplied input to the
last seen2020-06-01
modified2020-06-02
plugin id25090
published2007-04-27
reporterThis script is Copyright (C) 2007-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/25090
titlePlesk Multiple Script locale_id Parameter Traversal Arbitrary File Access