5
CVSSv2

CVE-2007-2268

Published: 25/04/2007 Updated: 08/03/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote malicious users to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.

Vulnerable Product Search on Vulmon Subscribe to Product

swsoft plesk 7.6.1

swsoft plesk 8.1.0

swsoft plesk 8.1.1

Exploits

source: wwwsecurityfocuscom/bid/23639/info Plesk is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application Information obtained may aid in further a ...