PT-2013-5255 · Parallels · Small Business Panel+1

Kingcope

·

Published

2013-07-18

·

Updated

2013-07-29

·

CVE-2013-4878

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Parallels Plesk Panel versions 9.0.x through 9.2.x Small Business Panel versions 10.x
Description The default configuration of the software has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request.
Recommendations For Parallels Plesk Panel versions 9.0.x through 9.2.x, update the ScriptAlias directive to properly restrict access to the phppath. For Small Business Panel versions 10.x, update the ScriptAlias directive to properly restrict access to the phppath.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4878

Affected Products

Parallels Plesk Panel
Small Business Panel