← All CVEs

CVE-2013-4878

high · 7.5

The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.

7.5
CVSS
31.1%
EPSS (exploit prob.)
98th
EPSS percentile
2013-07-18
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
parallelsparallels_plesk_panel9.0
parallelsparallels_plesk_panel9.2
parallelsparallels_small_business_panel10.0
linuxlinux_kernelall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-4878