7.5
CVE-2013-4878
- EPSS 31.07%
- Veröffentlicht 18.07.2013 16:51:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Parallels ≫ Parallels Plesk Panel Version9.0
Parallels ≫ Parallels Plesk Panel Version9.2
Parallels ≫ Parallels Small Business Panel Version10.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 31.07% | 0.98 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://www.kb.cert.org/vuls/id/673343
http://kb.parallels.com/116241
http://seclists.org/fulldisclosure/2013/Jun/21