Unrated severityNVD Advisory· Published Jul 18, 2013· Updated Apr 29, 2026
CVE-2013-4878
CVE-2013-4878
Description
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.
Affected products
3cpe:2.3:a:parallels:parallels_plesk_panel:9.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:parallels:parallels_plesk_panel:9.0:*:*:*:*:*:*:*
- cpe:2.3:a:parallels:parallels_plesk_panel:9.2:*:*:*:*:*:*:*
- cpe:2.3:a:parallels:parallels_small_business_panel:10.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- kb.parallels.com/116241nvdVendor Advisory
- www.kb.cert.org/vuls/id/673343nvdUS Government Resource
- seclists.org/fulldisclosure/2013/Jun/21nvd
News mentions
0No linked articles in our index yet.