Swsoft's vulnerability profile centers on a narrow line of web hosting control panels and management tools, including Plesk and Confixx, that occupy a prominent niche in the hosting and domain-administration infrastructure. The recurring weakness classes—cross-site scripting, code injection, and SQL injection—reflect the inherent risks of web-facing administrative interfaces, and vulnerabilities affecting this vendor have a strong tendency to acquire public exploit code. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Swsoft over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5028MEDIUM Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directorie | Sep 27, 2006 | 5.0 | 46 | NO | YES |
CVE-2001-0476HIGH Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a | Jun 27, 2001 | 7.5 | 32 | NO | YES |
CVE-2007-4892HIGH Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie | Sep 14, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-1754HIGH SQL injection vulnerability in index.php in SWSoft Confixx 3.0.6, 3.0.8, and 3.1.2 allows remote attackers to execute arbitrary SQL commands via the SID parameter. | Apr 13, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6451MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1 | Dec 10, 2006 | 6.8 | 27 | NO | YES |
CVE-2007-2268MEDIUM Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id | Apr 25, 2007 | 5.0 | 23 | NO | YES |
CVE-2006-2423MEDIUM Cross-site scripting (XSS) vulnerability in ftplogin/index.php in Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the login parameter. | May 17, 2006 | 4.3 | 21 | NO | YES |
CVE-2004-2702MEDIUM Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. | Dec 31, 2004 | 4.3 | 21 | NO | YES |
CVE-2006-3348HIGH Multiple SQL injection vulnerabilities in HSPcomplete 3.2.2 and 3.3 Beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) type parameter in report.p | Jul 3, 2006 | 7.5 | 19 | NO | NO |
CVE-2005-1302HIGH SQL injection vulnerability in Confixx 3.08 and earlier allows remote attackers to execute arbitrary SQL commands via the "change user" field. | May 2, 2005 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Swsoft.
Media articles that mention a CVE ID that affects a product developed by Swsoft — matched by CVE ID, not by vendor name.