• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

High Security Flaw !!! Please read, all.

Status
Not open for further replies.
3

3ASistemi

Guest
Hi all,
Some weeks ago someone hacked our webserver...

We've made some researches and test and we've found a security flaw on the following pages:

login.php3
login_up.php
top.php3

This flaw can permit an attacker to read files that are stored on the hd.

Example:

https://URLOFTHEPLESKPANEL/login_up...cale_id=../../../../../../../../boot.ini.jpg

We've tested it with plesk for windows 8.1 and 8.1.1, but we didn't found any information on this exploit. Is there already an hotfix? How can we solve that?
 
Unbelievable that nobody gives any response on this. That's why i really think that the majority of all users here don't care about security.

Can confirm the above, this is really a big issue.

Can someone of Plesk also check on this and give us at least any response ?

I believe Plesk stores the admin password in plain text in a file. With the above issue it is possible to retreive this file ?
 
I can't duplicate on my CentOS installation (changing to a unix file and not the Win file), so this may be a Windows only flaw.

Did anyone open a support ticket?
 
see the picture, please

Please,
swsoft programmers, see the picture attach,
and resolve this BIG HOLE security...

The problem persist in 8.1 and 8.1.1 versione
of Windows Plesk.
P.S. The 8.1.1 is a fresh installation of windows
server 2003 web edition and plesk...


... excuse me, why don't see my attach ?
The picture is 87Kb ???
 
Status
Not open for further replies.
Back
Top