|
|
Info |
Last Modified |
| 5 months ago |
|
|
|
|
Description |
Plesk contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the program not properly sanitizing the PLESKSESSID cookie before being used in SQL statements. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
OSVDB:
Web Related
|
|
Solution |
Currently, there are no known workarounds or upgrades to correct this issue. However, SWSoft has released a patch to address this vulnerability.
|
|
Products |
|
Plesk for Windows
 |
7.6.1 |
8.1.0 |
8.1.0.3 |
8.1.1.2 |
8.2 |
|
|
|
|
Credit |
- Nick I Merritt - HackerSafe Labs
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|