VinaCIS Network
Friday, 30 July 2010
VinaCIS .NETWORK
Home arrow Security arrow Plesk divulges access password

Articles
Webmaster
Security
Solved problems
Common problems
Linux problems
Windows problems
Plesk Control Panel
Advertise with us
Polls
Which Control Panel software would you prefer to use ?
 
Login Form





Lost Password?
No account yet? Register
Plesk divulges access password PDF Print E-mail
User Rating: / 0
PoorBest 

 Sample ImageA vulnerability in Plesk, a configuration tool for web servers and web hosting, may divulge Plesk's system password. The only thing you need to do is look for phpinfo and another string in a search in Yahoo or Google. Your password is then displayed in the hits along with data for the PHP and server configuration.

While the exact cause of the error is not known, the flaw apparently only occurs after an upgrade to Plesk 8.1 when the server has not been rebooted. A search conducted by heise Security for potentially vulnerable systems therefore only revealed a few hundred servers worldwide. The vendor Swsoft has been informed about the problem and has provided a hotfix that registered customers can download. The patch can also be installed via the autoupdate function. The developers of Plesk recommend changing the password.

 
< Prev   Next >

Top!