PT-2007-3603 · Parallels · Plesk
Published
2007-04-25
·
Updated
2011-03-08
·
CVE-2007-2268
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Plesk for Windows versions 7.6.1, 8.1.0, 8.1.1
Description
The issue allows remote attackers to read arbitrary files due to multiple directory traversal vulnerabilities. This can be achieved by including a .. (dot dot) in the
locale id parameter to specific API endpoints, such as "login.php3" or "login up.php3".Recommendations
For versions 7.6.1, 8.1.0, and 8.1.1, consider restricting access to the
login.php3 and login up.php3 endpoints until a fix is available.
As a temporary workaround, avoid using the locale id parameter in the affected API endpoints.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Plesk