Product: Plesk control panel
Version: <= 8.0.0
Vendor: SWSoft Inc.
URL: http://www.swsoft.com/en/products/plesk/
VULNERABILITY CLASS: XSS
[Product Description]
Plesk is comprehensive server management software developed specifically for the Hosting Service Industry with the assistance of Web hosting professionals.
[Summary]
An attacker can exploit it by compromising the values of the parameter
"file" in filemanager.php.
This can be used to take advantage of the trust between a client and server
allowing the malicious user to execute malicious JavaScript on
the client's machine when client is logged into control panel.
[Exploit]
https://target.xxx:8443/filemanager/filemanager.php?cmd=chdir&file=<scri
pt>alert();</script>
[Credits]
INVENT