• The new Python extension is now available. It allows customers to deploy and manage WSGI-based Python applications on their websites directly from Plesk.
  • Debian 11 has reached its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.81 is the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

How to disable PHP "exec" & co. server-wide on the OS level

Bitpalast

Plesk addicted!
Plesk Guru
Security tests have shown that without a disabled exec command in the php.ini settings of each account customers can easily read-access files like /etc/passwd and manipulate other files on the host machine.

We would like to eliminate the need to have a disabled_functions=exec... listed in the individual php.ini settings. Can this command be disabled for all PHP instances regardless what a user enters into his php.ini settings?
 
Back
Top