CVE-2013-4878
Summary
| CVE | CVE-2013-4878 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-07-18 16:51:56 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Application | Parallels | Parallels Plesk Panel | 9.0 | All | All | All |
| Application | Parallels | Parallels Plesk Panel | 9.2 | All | All | All |
| Application | Parallels | Parallels Small Business Panel | 10.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability Note VU#673343 - Parallels Plesk Panel phppath/php vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Full Disclosure: Plesk Apache Zeroday Remote Exploit | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| KB Parallels: Parallels Plesk Panel: phppath/PHP vulnerability | af854a3a-2127-422b-91ae-364da2661108 | kb.parallels.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.