CVE-2013-4878: High severity plesk vulnerability
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4878?
CVE-2013-4878 is rated as having a high severity due to the ease of exploitation leading to arbitrary code execution.
How do I fix CVE-2013-4878?
To fix CVE-2013-4878, update the Parallels Plesk Panel or Small Business Panel to the latest version where this vulnerability is patched.
What versions are affected by CVE-2013-4878?
CVE-2013-4878 affects Parallels Plesk Panel versions 9.0.x and 9.2.x, as well as Small Business Panel version 10.x on UNIX.
What type of vulnerability is CVE-2013-4878?
CVE-2013-4878 is a remote code execution vulnerability caused by an improper ScriptAlias directive in the default configuration.
Can CVE-2013-4878 be exploited remotely?
Yes, CVE-2013-4878 can be exploited remotely by attackers sending specially crafted requests.