Bitrix / Bitrix Site Manager
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2006-2479 | The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers to obtain sensitive… | MEDIUM | 5.0 | May 19, 2006 |
| CVE-2006-2478 | Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request. NOTE: this issue has… | MEDIUM | 5.0 | May 19, 2006 |
| CVE-2006-2477 | Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitrary web script or HT… | MEDIUM | 4.9 | May 19, 2006 |
| CVE-2006-2476 | Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive in… | MEDIUM | 5.0 | May 19, 2006 |
| CVE-2005-1996 | PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMEN… | MEDIUM | 5.0 | Jun 20, 2005 |
| CVE-2005-1995 | Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_error.php, which rev… | MEDIUM | 5.0 | Jun 20, 2005 |
Showing 1 to 6 of 6 CVEs