Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-4878

Опубликовано: 18 июл. 2013
Источник: nvd
CVSS2: 7.5
EPSS Средний

Описание

The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:parallels:parallels_plesk_panel:9.0:*:*:*:*:*:*:*
cpe:2.3:a:parallels:parallels_plesk_panel:9.2:*:*:*:*:*:*:*
cpe:2.3:a:parallels:parallels_small_business_panel:10.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

EPSS

Процентиль: 95%
0.17235
Средний

7.5 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.

EPSS

Процентиль: 95%
0.17235
Средний

7.5 High

CVSS2

Дефекты

CWE-264