Vulnerability Description
The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remote attackers to execute arbitrary PHP code via a request containing crafted environment variables.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Parallels | Parallels Plesk Panel | 11.0.9 |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/310500US Government Resource
- http://www.kb.cert.org/vuls/id/310500US Government Resource
FAQ
What is CVE-2013-0132?
CVE-2013-0132 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remote attackers to execute arbitrary PHP code via a request containing cra...
How severe is CVE-2013-0132?
CVE-2013-0132 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-0132?
Check the references section above for vendor advisories and patch information. Affected products include: Parallels Parallels Plesk Panel.