PT-2006-5769 · Swsoft · Plesk
Guanyu
·
Published
2006-09-27
·
Updated
2018-10-17
·
CVE-2006-5028
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SWsoft Plesk versions 7.5 through 7.6
Description
A directory traversal issue exists, allowing remote attackers to list arbitrary directories by using a ../ (dot dot slash) in the
file parameter within a 'chdir' action in the filemanager/filemanager.php file.Recommendations
For SWsoft Plesk versions 7.5 through 7.6, restrict access to the filemanager/filemanager.php file until a fix is available, and avoid using the
file parameter in the 'chdir' action with untrusted input.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Plesk