RETIRED: Parallels Plesk Panel Arbitrary PHP Code Injection Vulnerability
BID:60351
Info
RETIRED: Parallels Plesk Panel Arbitrary PHP Code Injection Vulnerability
| Bugtraq ID: | 60351 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2013 12:00AM |
| Updated: | Jun 07 2013 10:15PM |
| Credit: | Kingcope |
| Vulnerable: |
Parallels Plesk Panel 8.6 Parallels Parallels Plesk Panel 9.3 |
| Not Vulnerable: | |
Discussion
Parallels Plesk Panel Arbitrary PHP Code Injection Vulnerability
Parallels Plesk Panel is prone to an arbitrary PHP code-injection vulnerability because the application fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected application.
The following versions are affected:
Parallels Plesk Panel 9.5.4
Parallels Plesk Panel 9.3
Parallels Plesk Panel 9.2
Parallels Plesk Panel 9.0
Parallels Plesk Panel 8.6
Parallels Plesk Panel is prone to an arbitrary PHP code-injection vulnerability because the application fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected application.
The following versions are affected:
Parallels Plesk Panel 9.5.4
Parallels Plesk Panel 9.3
Parallels Plesk Panel 9.2
Parallels Plesk Panel 9.0
Parallels Plesk Panel 8.6
Exploit / POC
Parallels Plesk Panel Arbitrary PHP Code Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following exploits are available:
Attackers can use a browser to exploit this issue.
The following exploits are available:
Solution / Fix
RETIRED: Parallels Plesk Panel Arbitrary PHP Code Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Parallels Plesk Panel Arbitrary PHP Code Injection Vulnerability
References:
References:
- Parallels Plesk Panel Homepage (Parallels)