Логотип exploitDog
product: "plesk"
Консоль
Логотип exploitDog

exploitDog

product: "plesk"

Количество 22

Количество 22

github логотип

GHSA-wmvv-q98g-f9c3

около 3 лет назад

Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3.

EPSS: Низкий
github логотип

GHSA-qp76-4p7c-6pvj

около 3 лет назад

Directory traversal vulnerability in top.php3 in SWsoft Plesk for Windows 8.1 and 8.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter.

EPSS: Низкий
github логотип

GHSA-pw46-jrhv-gmmq

около 3 лет назад

Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie to (1) login.php3 or (2) auth.php3.

EPSS: Низкий
github логотип

GHSA-j299-xg3x-fqhp

больше 1 года назад

Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-g6h8-g3g9-q69c

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) get_password.php or (2) login_up.php3.

EPSS: Низкий
github логотип

GHSA-f96r-wmpc-994r

больше 1 года назад

Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-cgvr-863q-564c

около 3 лет назад

Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.

EPSS: Низкий
github логотип

GHSA-84hm-26hq-gff5

больше 3 лет назад

Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-46f7-973c-q8p8

около 3 лет назад

Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.

EPSS: Низкий
github логотип

GHSA-3hhp-w7c3-gjq2

больше 3 лет назад

Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-4931

больше 1 года назад

Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2023-0829

больше 1 года назад

Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2021-45008

больше 3 лет назад

Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2021-45007

больше 3 лет назад

Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2008-6984

почти 16 лет назад

Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2007-4892

почти 18 лет назад

Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie to (1) login.php3 or (2) auth.php3.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-2269

около 18 лет назад

Directory traversal vulnerability in top.php3 in SWsoft Plesk for Windows 8.1 and 8.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-2268

около 18 лет назад

Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-6451

больше 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) get_password.php or (2) login_up.php3.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-2702

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-wmvv-q98g-f9c3

Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3.

0%
Низкий
около 3 лет назад
github логотип
GHSA-qp76-4p7c-6pvj

Directory traversal vulnerability in top.php3 in SWsoft Plesk for Windows 8.1 and 8.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter.

0%
Низкий
около 3 лет назад
github логотип
GHSA-pw46-jrhv-gmmq

Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie to (1) login.php3 or (2) auth.php3.

1%
Низкий
около 3 лет назад
github логотип
GHSA-j299-xg3x-fqhp

Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-g6h8-g3g9-q69c

Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) get_password.php or (2) login_up.php3.

0%
Низкий
около 3 лет назад
github логотип
GHSA-f96r-wmpc-994r

Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-cgvr-863q-564c

Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.

7%
Низкий
около 3 лет назад
github логотип
GHSA-84hm-26hq-gff5

Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-46f7-973c-q8p8

Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.

5%
Низкий
около 3 лет назад
github логотип
GHSA-3hhp-w7c3-gjq2

Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-4931

Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-0829

Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2021-45008

Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-45007

Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2008-6984

Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3.

CVSS2: 5.8
0%
Низкий
почти 16 лет назад
nvd логотип
CVE-2007-4892

Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie to (1) login.php3 or (2) auth.php3.

CVSS2: 7.5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2007-2269

Directory traversal vulnerability in top.php3 in SWsoft Plesk for Windows 8.1 and 8.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter.

CVSS2: 5
0%
Низкий
около 18 лет назад
nvd логотип
CVE-2007-2268

Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.

CVSS2: 5
5%
Низкий
около 18 лет назад
nvd логотип
CVE-2006-6451

Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) get_password.php or (2) login_up.php3.

CVSS2: 6.8
0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2004-2702

Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.

CVSS2: 4.3
7%
Низкий
больше 20 лет назад

Уязвимостей на страницу