01642 06 11 11 Arrange Call

Improper ScriptAlias Directive in Parallels Plesk Panel and Small Business Panel Allows Remote Code Execution

CVE-2013-4878 · HIGH

CVE-2013-4878

The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.

Learn more about our Web Application Penetration Testing UK.