Plesk Server Administrator PHP Source Disclosure Vulnerability
BID:3737
Info
Plesk Server Administrator PHP Source Disclosure Vulnerability
| Bugtraq ID: | 3737 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1222 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 21 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Discovered and posted to Bugtraq by <[email protected]>. |
| Vulnerable: |
Plesk Plesk Server Administrator 1.0 |
| Not Vulnerable: |
Plesk Plesk Server Administrator 2.0 |
Discussion
Plesk Server Administrator PHP Source Disclosure Vulnerability
Plesk Server Administrator (PSA) is web based software that enables remote administration of web servers. It can be used on Linux and other systems that support PHP.
Due to an input validation error in Plesk Server Administrator, it is possible for a remote attacker to make a specially crafted web request which will display PHP source code.
This is acheivable by connecting to a host (using the IP address rather than the domain name), and submitting a request for a known PHP file along with a valid username.
Plesk Server Administrator (PSA) is web based software that enables remote administration of web servers. It can be used on Linux and other systems that support PHP.
Due to an input validation error in Plesk Server Administrator, it is possible for a remote attacker to make a specially crafted web request which will display PHP source code.
This is acheivable by connecting to a host (using the IP address rather than the domain name), and submitting a request for a known PHP file along with a valid username.
Exploit / POC
Plesk Server Administrator PHP Source Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Plesk Server Administrator PHP Source Disclosure Vulnerability
Solution:
PSA version 2.0 is not vulnerable to this issue and Plesk encourages users to upgrade.
Solution:
PSA version 2.0 is not vulnerable to this issue and Plesk encourages users to upgrade.