Lucene search

K
cve[email protected]CVE-2012-1557
HistoryMar 12, 2012 - 7:55 p.m.

CVE-2012-1557

2012-03-1219:55:01
CWE-89
web.nvd.nist.gov
28
cve-2012-1557
sql injection
parallels plesk panel
remote attackers
security vulnerability
exploited in the wild

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.7 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

74.5%

SQL injection vulnerability in admin/plib/api-rpc/Agent.php in Parallels Plesk Panel 7.x and 8.x before 8.6 MU#2, 9.x before 9.5 MU#11, 10.0.x before MU#13, 10.1.x before MU#22, 10.2.x before MU#16, and 10.3.x before MU#5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in March 2012.

Affected configurations

NVD
Node
parallelsparallels_plesk_panelMatch7.0
OR
parallelsparallels_plesk_panelMatch7.6.1
OR
parallelsparallels_plesk_panelMatch8.0
OR
parallelsparallels_plesk_panelMatch8.1
OR
parallelsparallels_plesk_panelMatch8.2
OR
parallelsparallels_plesk_panelMatch8.3
OR
parallelsparallels_plesk_panelMatch8.4
OR
parallelsparallels_plesk_panelMatch8.6
Node
parallelsparallels_plesk_panelMatch9.0
OR
parallelsparallels_plesk_panelMatch9.2
OR
parallelsparallels_plesk_panelMatch9.3
OR
parallelsparallels_plesk_panelMatch9.5
OR
parallelsparallels_plesk_panelMatch9.5.4
Node
parallelsparallels_plesk_panelMatch10.0.1mu_\#10
OR
parallelsparallels_plesk_panelMatch10.0.1mu_\#11
OR
parallelsparallels_plesk_panelMatch10.0.1mu_\#2
OR
parallelsparallels_plesk_panelMatch10.0.1mu_\#3
OR
parallelsparallels_plesk_panelMatch10.0.1mu_\#5
OR
parallelsparallels_plesk_panelMatch10.0.1mu_\#7
Node
parallelsparallels_plesk_panelMatch10.1.1mu_\#10
OR
parallelsparallels_plesk_panelMatch10.1.1mu_\#11
OR
parallelsparallels_plesk_panelMatch10.1.1mu_\#12
OR
parallelsparallels_plesk_panelMatch10.1.1mu_\#13
OR
parallelsparallels_plesk_panelMatch10.1.1mu_\#15
OR
parallelsparallels_plesk_panelMatch10.1.1mu_\#16
OR
parallelsparallels_plesk_panelMatch10.1.1mu_\#17
OR
parallelsparallels_plesk_panelMatch10.1.1mu_\#18
OR
parallelsparallels_plesk_panelMatch10.1.1mu_\#19
OR
parallelsparallels_plesk_panelMatch10.1.1mu_\#20
Node
parallelsparallels_plesk_panelMatch10.2.0mu_\#1
OR
parallelsparallels_plesk_panelMatch10.2.0mu_\#10
OR
parallelsparallels_plesk_panelMatch10.2.0mu_\#11
OR
parallelsparallels_plesk_panelMatch10.2.0mu_\#12
OR
parallelsparallels_plesk_panelMatch10.2.0mu_\#2
OR
parallelsparallels_plesk_panelMatch10.2.0mu_\#3
OR
parallelsparallels_plesk_panelMatch10.2.0mu_\#4
OR
parallelsparallels_plesk_panelMatch10.2.0mu_\#5
OR
parallelsparallels_plesk_panelMatch10.2.0mu_\#7
OR
parallelsparallels_plesk_panelMatch10.2.0mu_\#8
OR
parallelsparallels_plesk_panelMatch10.2.0mu_\#9
Node
parallelsparallels_plesk_panelMatch10.3.1mu_\#2
OR
parallelsparallels_plesk_panelMatch10.3.1mu_\#3
OR
parallelsparallels_plesk_panelMatch10.3.1mu_\#4

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.7 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

74.5%

Related for CVE-2012-1557