Hope others in the forum find this post before they get hacked. Parallels has sent no notice about this to Plesk users but a microupdate #24 was released three days ago to fix what is described as "major security fixes" to 9.5.4:
http://kb.parallels.com/114891
There appear to be two public-facing php files (index.php, login_up.php) that are replaced and eight other Plesk admin-related files replaced.
v10 users should verify that they got microupdate 43 and 44 too, hopefully automated:
http://download1.parallels.com/Ples...el-10-linux-updates-release-notes.html#104444
http://kb.parallels.com/114891
There appear to be two public-facing php files (index.php, login_up.php) that are replaced and eight other Plesk admin-related files replaced.
v10 users should verify that they got microupdate 43 and 44 too, hopefully automated:
http://download1.parallels.com/Ples...el-10-linux-updates-release-notes.html#104444