PT-2013-5255 · Parallels · Small Business Panel+1
Kingcope
·
Published
2013-07-18
·
Updated
2013-07-29
·
CVE-2013-4878
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Parallels Plesk Panel versions 9.0.x through 9.2.x
Small Business Panel versions 10.x
Description
The default configuration of the software has an improper ScriptAlias directive for
phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request.Recommendations
For Parallels Plesk Panel versions 9.0.x through 9.2.x, update the ScriptAlias directive to properly restrict access to the
phppath.
For Small Business Panel versions 10.x, update the ScriptAlias directive to properly restrict access to the phppath.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Parallels Plesk Panel
Small Business Panel