CVE-2013-4878 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 31.1% (pctl 98)
Patch early
A public exploit exists.
Description
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 31.07% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-07-18 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| linux | linux kernel |
| parallels | parallels plesk panel |
| parallels | parallels small business panel |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Plesk < 9.5.4 - Remote Command Execution | 2013-06-05 |
References
→ the Explorer · watch your stack · NVD