Description
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.
Remediation
References
Related Vulnerabilities
GlassFish Improper Input Validation Vulnerability (CVE-2015-3237)
WordPress Plugin Beer Recipes Cross-Site Scripting (1.0)
Dotclear Improper Access Control Vulnerability (CVE-2015-8832)
MySQL CVE-2020-14632 Vulnerability (CVE-2020-14632)
Oracle Database Server CVE-2014-4300 Vulnerability (CVE-2014-4300)