CVE-2013-0132: Code Injection
The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remote attackers to execute arbitrary PHP code via a request containing crafted environment variables.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0132?
CVE-2013-0132 is classified as a high severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2013-0132?
To fix CVE-2013-0132, upgrade Parallels Plesk Panel to a version beyond 11.0.9 where the vulnerability has been patched.
What types of attacks could exploit CVE-2013-0132?
CVE-2013-0132 could be exploited through user-assisted remote attacks allowing execution of crafted PHP code.
Which software is affected by CVE-2013-0132?
CVE-2013-0132 specifically affects Parallels Plesk Panel version 11.0.9.
Can CVE-2013-0132 be mitigated without upgrading?
Mitigating CVE-2013-0132 without upgrading is difficult, but restricting user permissions may reduce risk.