这段描述的是一个在 Plesk 中由“检查时”与“使用时”(TOCTOU)竞态条件引发的安全漏洞,具体表现为对符号链接的不安全跟随,从而导致本地权限提升至 root 级别,攻击者可通过任意文件或目录的所有权接管获得 root 权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65639 | 9.5 CRITICAL | ConfigServer Security & Firewall 16.30以下OS命令注入 |
| CVE-2026-65638 | 9.2 CRITICAL | ConfigServer Security & Firewall 16.30前 远程未认证RCE |
| CVE-2026-68487 | Plesk Backup Manager 路径遍历致root任意文件写入 |
No comments yet