PT-2013-5255 · Parallels · Small Business Panel+1
Kingcope
·
Publicado
2013-07-18
·
Atualizado
2013-07-29
·
CVE-2013-4878
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Parallels Plesk Panel versions 9.0.x through 9.2.x
Small Business Panel versions 10.x
Description
The default configuration of the software has an improper ScriptAlias directive for
phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request.Recommendations
For Parallels Plesk Panel versions 9.0.x through 9.2.x, update the ScriptAlias directive to properly restrict access to the
phppath.
For Small Business Panel versions 10.x, update the ScriptAlias directive to properly restrict access to the phppath.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Parallels Plesk Panel
Small Business Panel