PT-2013-5255 · Parallels · Small Business Panel+1

Kingcope

·

Publicado

2013-07-18

·

Atualizado

2013-07-29

·

CVE-2013-4878

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Parallels Plesk Panel versions 9.0.x through 9.2.x Small Business Panel versions 10.x
Description The default configuration of the software has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request.
Recommendations For Parallels Plesk Panel versions 9.0.x through 9.2.x, update the ScriptAlias directive to properly restrict access to the phppath. For Small Business Panel versions 10.x, update the ScriptAlias directive to properly restrict access to the phppath.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4878

Produtos afetados

Parallels Plesk Panel
Small Business Panel