VulnerabilityModified
CVE-2001-1222
Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain.
MEDIUM 5.0EPSS 1.60%
Does this matter?
Lower severity and a low EPSS score (1.60%). Track it; it rarely justifies an emergency change on its own.
Description
Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.60% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- plesk/plesk server administrator
- Source
- cve@mitre.org
References
- http://www.iss.net/security_center/static/7735.phpPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/246861Patch, Vendor Advisory
- http://www.securityfocus.com/bid/3737Patch, Vendor Advisory
- http://www.iss.net/security_center/static/7735.phpPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/246861Patch, Vendor Advisory
- http://www.securityfocus.com/bid/3737Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.