VYPR
Unrated severityNVD Advisory· Published Sep 14, 2007· Updated Jun 16, 2026

CVE-2007-4892

CVE-2007-4892

Description

Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie to (1) login.php3 or (2) auth.php3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Swsoft/Plesk5 versions
    cpe:2.3:a:swsoft:plesk:7.6.1:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:swsoft:plesk:7.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:swsoft:plesk:8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:swsoft:plesk:8.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:swsoft:plesk:8.2:*:*:*:*:*:*:*
    • (no CPE)range: 7.6.1, 8.1.0, 8.1.1, and 8.2.0

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.