CVE-2006-5028

SWsoft Plesk 7.5 Reload and 7.6 - Directory Traversal via File Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5028. PoCs published by GuanYu.

AI-analyzed exploit summary The provided text describes a directory traversal vulnerability in PLESK versions 7.5 Reload and prior, as well as 7.6 for Windows. The vulnerability allows an attacker to retrieve arbitrary files by manipulating the 'file' parameter in the URL.

Description

Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directories via a ../ (dot dot slash) in the file parameter in a chdir action.

Exploits (1)

exploitdb WRITEUP VERIFIED
by GuanYu · textwebappsphp
https://www.exploit-db.com/exploits/28647

The provided text describes a directory traversal vulnerability in PLESK versions 7.5 Reload and prior, as well as 7.6 for Windows. The vulnerability allows an attacker to retrieve arbitrary files by manipulating the 'file' parameter in the URL.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: PLESK 7.5 Reload and prior, 7.6 for Windows
No auth needed
Prerequisites: Access to the vulnerable PLESK filemanager interface
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22058
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20155
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/446730/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1643
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/29134
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/470509/100/0/threaded

Scores

EPSS 0.4648
EPSS Percentile 98.7%

Details

Status published
Products (2)
swsoft/plesk 7.6
swsoft/plesk_reload 7.5
Published Sep 27, 2006
Tracked Since Feb 18, 2026