First published: Thu Jul 18 2013(Updated: )
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plesk | =9.0 | |
Plesk | =9.2 | |
Parallels Plesk Small Business Panel | =10.0 | |
Linux Kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4878 is rated as having a high severity due to the ease of exploitation leading to arbitrary code execution.
To fix CVE-2013-4878, update the Parallels Plesk Panel or Small Business Panel to the latest version where this vulnerability is patched.
CVE-2013-4878 affects Parallels Plesk Panel versions 9.0.x and 9.2.x, as well as Small Business Panel version 10.x on UNIX.
CVE-2013-4878 is a remote code execution vulnerability caused by an improper ScriptAlias directive in the default configuration.
Yes, CVE-2013-4878 can be exploited remotely by attackers sending specially crafted requests.