• The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Possible bug in php-xslt rpm package

gijsbert

Basic Pleskian
If you are planning to use the SiteBuilder application for creating web sites, additional packages needs to be installed. One of these packages is:

php-xslt-1.0-0.i386.rpm

Please note that after installing the php-xslt rpm, the uid/gid of the /etc and /usr directory becomes apache:apache. I can reproduce this by simply installing the php-xslt rpm provided by plesk.

If someone is able to abuse a script on your server (i.e. phpBB), they (apache) have access /etc/ and /usr directory. Not good!!!

Gijsbert Rochat
[email protected]

Sitebytes BV
www.sitebytes.nl
 
Back
Top