Release date:
Updated on:
Affected Systems:
Parallels Plesk Panel 8.6
Parallels Plesk Panel 7.6.1
Parallels Plesk Panel 10.3.1
Parallels Plesk Panel 9.5
Parallels Plesk Panel 9.3
Parallels Plesk Panel 10.3
Parallels Plesk Panel 10.2
Parallels Plesk Panel 10.1
Parallels Plesk Panel 10.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52267
CVE (CAN) ID: CVE-2012-1557
Parallels Plesk Panel is a Host Control Panel solution that allows website owners to enjoy a faster website and faster mobile access experience, and has a complete product line that keeps pace with your host business growth.
Parallels Plesk Panel 7.6.1-10.3.1 has the SQL injection vulnerability in the implementation of admin/plib/api-rpc/Agent. php, which allows remote attackers to execute arbitrary SQL commands.
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Parallels
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.parallels.com/cn/products/plesk/
Http://download1.parallels.com/Plesk/PP10/parallels-plesk-panel-10-linux-updates-release-notes.html#10216
Http://download1.parallels.com/Plesk/PP10/parallels-plesk-panel-10-windows-updates-release-notes.html#10216