Vulnerability record · CVE-2006-5028 · published 27 September 2006
CVE-2006-5028: Plesk filemanager.php directory traversal allows arbitrary directory listing
Swsoft · Plesk
SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows contain a directory traversal flaw in filemanager/filemanager.php. A ../ sequence in the file parameter of a chdir action lets a remote attacker list directories outside the intended web root. The record does not specify which Plesk builds are patched or whether later versions are affected.
Description
Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directories via a ../ (dot dot slash) in the file parameter in a chdir action.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
medium priorityThe flaw is remotely reachable without authentication and has a public exploit reference and high EPSS score, but it only discloses directory listings with no integrity or availability impact.
What it is
SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows contain a directory traversal flaw in filemanager/filemanager.php. A ../ sequence in the file parameter of a chdir action lets a remote attacker list directories outside the intended web root. The record does not specify which Plesk builds are patched or whether later versions are affected.
Impact
An attacker gains read-only disclosure of directory contents on the server, which can reveal file and path names useful for planning further attacks. There is no reported integrity or availability impact.
Attack surface
Reachable over the network through the filemanager component's chdir action; the CVSS vector AV:N/AC:L/Au:N/C:P/I:N/A:N indicates no authentication and no user interaction are required. The description does not state whether the endpoint is exposed only to authenticated Plesk users or to any network client.
Exploitation
CISA KEV does not list this CVE, but a SecurityFocus BID reference is tagged Exploit and EPSS reports a 30-day probability of 0.466 at the 98.8th percentile, indicating meaningful observed likelihood. No ransomware use is documented.
What to do
- Apply the vendor fix for Plesk 7.5 Reload and 7.6 on Windows; if no patch is available, upgrade to a supported Plesk release.
- Restrict network access to the filemanager component to trusted administrative networks or VPN only.
- Normalize and reject path traversal sequences (../, encoded variants) in the file parameter before any filesystem call.
- Run the Plesk web service with least privilege so directory listing cannot reach sensitive paths.
- Monitor vendor advisories for this product line since the record does not identify a fixed version.
Detection
- Search web logs for requests to filemanager/filemanager.php containing chdir actions and ../ or encoded traversal sequences in the file parameter.
- Alert on directory-listing responses from the filemanager endpoint, especially those returning paths outside the expected web root.
- Correlate repeated traversal attempts from a single source IP against the filemanager path.
- Review Plesk filemanager access logs for unusual file parameter values or high-volume enumeration patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5028 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-5028), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.