CVE-2013-4878
57Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 31%
from disclosure to weapon0 days
Published on NVDJul 18
1st PoCJun 5
VulnCheckJun 6
exploitation probability
31%top 2% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/25986⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.