peter bassill · operator
$ cve CVE-2013-4878 JSON

CVE-2013-4878 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 31.1% (pctl 98)

Patch early

A public exploit exists.

Description

The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS31.07% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2013-07-18
Last modified2026-06-16

Affected (3)

VendorProduct
linuxlinux kernel
parallelsparallels plesk panel
parallelsparallels small business panel

Public exploits

SourceTitleDate
exploit-dbPlesk < 9.5.4 - Remote Command Execution2013-06-05

References

→ the Explorer  ·  watch your stack  ·  NVD