• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

[PLESK 7.5 Reload] & [PLESK 7.6 for MS Windows] path passing and disclosure vulnerabi

lvalics

Silver Pleskian
Plesk Guru
/*--------------------------------------
[PLESK 7.5 Reload (and lower) & PLESK 7.6 for M$ Windows path passing and disclosure]
Discovered By: GuanYu
Email: [email protected]
Website: HVA (http://www.vnhacker.org)
--------------------------------------*/

-| Description: |-

PLESK is a powerful web control panel, site builder... You can see more about it at:

http://www.swsoft.com/en/products/plesk/switch/ .
So, i have found a security hole - path passing and disclosure - of this product (version

[PLESK 7.5 Reload] and [PLESK 7.6 for M$ Windows]) in the file : filemanager.php


-| What an attacker can do? |-

The attacker can take advantage of this hole to access the parent folder (which he havent

authorization).
Like this:

https://[stie]:8443/filemanager/filemanager.php?cmd=chdir&file=../

That URL will show him (attacker) the parent folder of his "web root" folder. Using more

"/../" characters, he'll go to up, up, and up folder so he can gain lot of important info.

-| How to fix it? |-

Upgrade to the PLESK 8.0 :D.

- End -

P/S: Sorry about my English, its to bad.
 
Back
Top