Plesk control panel versions 8.0.0 and below suffer from a cross site scripting flaw.
1940826459537f4a61a1db36f39692d78500639e1bfdbeab4141c8f0091c9f2e
Product: Plesk control panel
Version: <= 8.0.0
Vendor: SWSoft Inc.
URL: http://www.swsoft.com/en/products/plesk/
VULNERABILITY CLASS: XSS
[Product Description]
Plesk is comprehensive server management software developed specifically for the Hosting Service Industry with the assistance of Web hosting professionals.
[Summary]
An attacker can exploit it by compromising the values of the parameter
"file" in filemanager.php.
This can be used to take advantage of the trust between a client and server
allowing the malicious user to execute malicious JavaScript on
the client's machine when client is logged into control panel.
[Exploit]
https://target.xxx:8443/filemanager/filemanager.php?cmd=chdir&file=<script>alert();</script>
[Credits]
INVENT