• Inviting everyone who uses WordPress management tools in Plesk
    The Plesk team is conducting a 60-minute research session that includes an interview and a moderated usability test.
    To participate, please use this link .
    Your experience will help shape product decisions and ensure the tools better support real-world use cases.

Horde barcode.php exploit

SacAutos

Regular Pleskian
Today I was reviewing my daily watchdog report and saw that a visitor had been able to get a copy of my /etc/passwd file via a horde exploit. After some research I found this old security alert:

http://securityreason.com/securityalert/8077

This is rather old. Why hasn't this been fixed? No wonder I'm seeing ftp login attempts with apparent "insider" knowledge of the user ids...

Plesk 9.5.4 on CentOS 5
 
Back
Top