VYPR
Unrated severityNVD Advisory· Published Sep 14, 2007· Updated Apr 23, 2026

CVE-2007-4892

CVE-2007-4892

Description

Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie to (1) login.php3 or (2) auth.php3.

Affected products

4
  • Swsoft/Plesk4 versions
    cpe:2.3:a:swsoft:plesk:7.6.1:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:swsoft:plesk:7.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:swsoft:plesk:8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:swsoft:plesk:8.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:swsoft:plesk:8.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.