CVE-2013-0132 Information

Description

The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry which allows user-assisted remote attackers to execute arbitrary PHP code via a request containing crafted environment variables.

Reference

http://www.kb.cert.org/vuls/id/310500

Share on: