PLESK Filemanager.PHP Directory Traversal Vulnerability
BID:20155
Info
PLESK Filemanager.PHP Directory Traversal Vulnerability
| Bugtraq ID: | 20155 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2006 12:00AM |
| Updated: | Sep 22 2006 10:31PM |
| Credit: | GuanYu is credited with the discovery of this vulnerability. |
| Vulnerable: |
Plesk Plesk Reload 7.5 Plesk Plesk for Windows 7.6 |
| Not Vulnerable: | |
Discussion
PLESK Filemanager.PHP Directory Traversal Vulnerability
PLESK is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
Versions 7.5 Reload (and prior) and 7.6 for Windows are vulnerable to this issue; other versions may also be affected.
PLESK is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
Versions 7.5 Reload (and prior) and 7.6 for Windows are vulnerable to this issue; other versions may also be affected.
Exploit / POC
PLESK Filemanager.PHP Directory Traversal Vulnerability
Attackers may exploit this vulnerability via a web client.
An example URI has been provided:
https://www.example.com:8443/filemanager/filemanager.php?cmd=chdir&file=../
Attackers may exploit this vulnerability via a web client.
An example URI has been provided:
https://www.example.com:8443/filemanager/filemanager.php?cmd=chdir&file=../
Solution / Fix
PLESK Filemanager.PHP Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Reportedly, the vendor has released fixes to address this issue. Symantec has not confirmed this.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Reportedly, the vendor has released fixes to address this issue. Symantec has not confirmed this.