CVE-2007-2268
SWsoft Plesk 7.6.1, 8.1.0, 8.1.1 - Directory Traversal via Locale ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2268. PoCs published by anonymous.
AI-analyzed exploit summary The provided text describes a directory traversal vulnerability in Plesk, where unsanitized input in the 'locale_id' parameter allows arbitrary file retrieval. The example URL demonstrates accessing 'boot.ini' via path traversal.
Description
Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.
Exploits (1)
The provided text describes a directory traversal vulnerability in Plesk, where unsanitized input in the 'locale_id' parameter allows arbitrary file retrieval. The example URL demonstrates accessing 'boot.ini' via path traversal.