Skip to content
Noroxi

Bitrix records

10 published records for vendor bitrix.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

10 records
  • CVE-2015-8358
    38Monitor

    Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execut

    CriticalCVSS 9.0Proof of conceptEPSS 7%

    bitrix · mpbuilderDec 16, 2015

  • CVE-2013-6788
    30Monitor

    The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it eas

    HighCVSS 7.5No exploitEPSS 2%

    bitrix · bitrix e-store moduleMay 30, 2014

  • CVE-2015-8357
    29Monitor

    Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary f

    MediumCVSS 6.5Proof of conceptEPSS 8%

    bitrix · xscanDec 16, 2015

  • modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by

    MediumCVSS 6.1No exploitEPSS 1%

    bitrix · bitrix24Jun 1, 2020

  • CVE-2006-2476
    21Monitor

    Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to

    MediumCVSS 5.0No exploitEPSS 2%

    bitrix · bitrix site managerMay 19, 2006

  • CVE-2006-2479
    21Monitor

    The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers

    MediumCVSS 5.0No exploitEPSS 2%

    bitrix · bitrix site managerMay 19, 2006

  • CVE-2006-2478
    20Monitor

    Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request.

    MediumCVSS 5.0No exploitEPSS 2%

    bitrix · bitrix site managerMay 19, 2006

  • CVE-2005-1996
    20Monitor

    PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via

    MediumCVSS 5.0No exploitEPSS 2%

    bitrix · bitrix site managerJun 15, 2005

  • CVE-2005-1995
    20Monitor

    Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_e

    MediumCVSS 5.0No exploitEPSS 1%

    bitrix · bitrix site managerJun 15, 2005

  • CVE-2006-2477
    19Monitor

    Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitra

    MediumCVSS 4.9No exploitEPSS 1%

    bitrix · bitrix site managerMay 19, 2006