First published: Wed Apr 25 2007(Updated: )
Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plesk Obsidian | =7.6.1 | |
Plesk Obsidian | =8.1.0 | |
Plesk Obsidian | =8.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2268 is classified as a medium-severity vulnerability due to its potential to allow unauthorized access to sensitive files.
To fix CVE-2007-2268, you should upgrade to a non-vulnerable version of SWsoft Plesk, specifically versions beyond 8.1.1.
CVE-2007-2268 affects SWsoft Plesk versions 7.6.1, 8.1.0, and 8.1.1 running on Windows.
CVE-2007-2268 can be exploited by remote attackers to perform directory traversal attacks, allowing them to access arbitrary files.
While CVE-2007-2268 is from 2007, systems that have not been updated remain vulnerable and should be secured immediately.