Show filters
73 Total Results
Displaying 1-10 of 73
Sort by:
Attacker Value
Unknown
CVE-2024-34014
Disclosure Date: November 11, 2024 (last updated November 12, 2024)
Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 818, Acronis Backup extension for Plesk (Linux) before build 599, Acronis Backup plugin for DirectAdmin (Linux) before build 181.
0
Attacker Value
Unknown
CVE-2024-8767
Disclosure Date: September 17, 2024 (last updated September 17, 2024)
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147.
0
Attacker Value
Unknown
CVE-2023-4931
Disclosure Date: November 27, 2023 (last updated December 02, 2023)
Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.
0
Attacker Value
Unknown
CVE-2023-0829
Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.
0
Attacker Value
Unknown
CVE-2021-45008
Disclosure Date: February 21, 2022 (last updated November 08, 2023)
Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users
0
Attacker Value
Unknown
CVE-2021-45007
Disclosure Date: February 20, 2022 (last updated November 08, 2023)
Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users
0
Attacker Value
Unknown
CVE-2019-18793
Disclosure Date: November 13, 2019 (last updated November 27, 2024)
Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter.
0
Attacker Value
Unknown
CVE-2013-4878
Disclosure Date: July 18, 2013 (last updated October 05, 2023)
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.
0
Attacker Value
Unknown
CVE-2013-0132
Disclosure Date: April 18, 2013 (last updated October 05, 2023)
The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remote attackers to execute arbitrary PHP code via a request containing crafted environment variables.
0
Attacker Value
Unknown
CVE-2013-0133
Disclosure Date: April 18, 2013 (last updated October 05, 2023)
Untrusted search path vulnerability in /usr/local/psa/admin/sbin/wrapper in Parallels Plesk Panel 11.0.9 allows local users to gain privileges via a crafted PATH environment variable.
0