Description
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.
Remediation
References
Related Vulnerabilities
WordPress Plugin Simple Schools Staff Directory Arbitrary File Upload (1.1)
WordPress Plugin Abandoned Cart Lite for WooCommerce SQL Injection (5.8.1)
WordPress Plugin Advanced Classifieds & Directory Pro Unspecified Vulnerability (1.6.5)
WordPress Plugin Contest Gallery-Photo Contest for WordPress Cross-Site Scripting (13.1.0.9)
WordPress Plugin Link Library Cross-Site Scripting (5.9.12.29)