We removed the agent.php from all Plesk servers but one. This server that did not have the agent.php removed was patched to the latest level. The Plesk scripts confirmed this, and manually checking the file also confirmed this. All passwords have been reset after the Plesk patch was run. However this server was running some DDOS scripts again.
I don't think the Plesk patch fully fixes the vulnerability. To be sure just remove the agent.php file.

Likes:


Quote
. 