CVE-2013-4878: Parallels Plesk Panel
High severity, CVSS 7.5. EPSS: 31.1% chance of exploitation in the next 30 days.
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.
Affected products
- Parallels Parallels Plesk Panel: version 9.0 only; version 9.2 only
- Parallels Parallels Small Business Panel: version 10.0 only
Published 2013-07-18. Last modified 2026-06-16.