Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Plesk | Swsoft | 7.6.1 (including) | 7.6.1 (including) |
Plesk | Swsoft | 8.1.0 (including) | 8.1.0 (including) |
Plesk | Swsoft | 8.1.1 (including) | 8.1.1 (including) |