CVE-2012-1557 describes a SQL injection vulnerability in Parallels Plesk Panel versions 7.x through 10.3.x, specifically within the admin/plib/api-rpc/Agent.php component. This flaw allows remote, unauthenticated attackers to execute arbitrary SQL commands. With a CVSS score of 7.5, it is considered highly severe, enabling potential compromise of confidentiality, integrity, and availability. The vulnerability was actively exploited in the wild in March 2012, notably in DarkLeech web server attacks, and has received some media coverage and community discussion, though no public exploit code is readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:a:parallels:parallels_plesk_panel:7.0:*:*:*:*:*:*:* | ||
7.6.1CPE matchmatch criteria | cpe:2.3:a:parallels:parallels_plesk_panel:7.6.1:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:parallels:parallels_plesk_panel:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:a:parallels:parallels_plesk_panel:8.1:*:*:*:*:*:*:* | ||
8.2CPE matchmatch criteria | cpe:2.3:a:parallels:parallels_plesk_panel:8.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.