• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Plesk Control Panel, has identified a SQL injection security.

D

dm.cummings

Guest
I received an email about Plesk Control Panel, has identified a SQL injection security. Since I am using Plesk 9.3 I reviewed this link : http://kb.parallels.com/en/113424

I installed this file to check to see if my server was safe : plesk_remote_vulnerability_checker.php

After running the script I got this error message : The file "/usr/local/psa/version" has not been found.

Can anyone help with this?
 
I'm also seeing this issue with "CentOS release 5.2 "
Some anonymous non-communicative individual installed it on my system, apparently in some non-standard way.
There is no /usr/local/psa directory.
I did find a /parallels/PSA_8.6.0 directory, but there's no "version" file in it either.
 
Last edited by a moderator:
Thanks - I was confused. The file is there.
My issue was that /etc/php.ini had "safe_mode = On" so PHP said it wasn't there.
When I changed it to "safe_mode = Off" everything worked OK.
 
Hi, applying this fix, I have this error a lot of times:
PHP Warning: Unexpected character in input: ' in /var/www/vhosts/domain.xx/plesk_remote_vulnerability_fix_deployer/plesk_remote_vulnerability_fix_deployer.php on line 57
and then:
PHP Parse error: syntax error, unexpected T_DNUMBER in /var/www/vhosts/domain.xx/plesk_remote_vulnerability_fix_deployer/plesk_remote_vulnerability_fix_deployer.php on line 57

Someone can help me?
Many thanks
 
Back
Top