Bitrix records
10 published records for vendor bitrix.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2015-8358Proof of concept | Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and executbitrix · mpbuilder · CWE-22 | Critical9.0 | — | 6.6% | Dec 16, 2015 |
30Monitor | CVE-2013-6788No exploit | The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easbitrix · bitrix e-store module · CWE-287 | High7.5 | — | 1.6% | May 30, 2014 |
29Monitor | CVE-2015-8357Proof of concept | Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary fbitrix · xscan · CWE-22 | Medium6.5 | — | 8.4% | Dec 16, 2015 |
24Monitor | CVE-2020-13758No exploit | modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by bitrix · bitrix24 · CWE-79 | Medium6.1 | — | 0.9% | Jun 1, 2020 |
21Monitor | CVE-2006-2476No exploit | Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to bitrix · bitrix site manager | Medium5.0 | — | 2.2% | May 19, 2006 |
21Monitor | CVE-2006-2479No exploit | The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers bitrix · bitrix site manager | Medium5.0 | — | 1.9% | May 19, 2006 |
20Monitor | CVE-2006-2478No exploit | Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request.bitrix · bitrix site manager | Medium5.0 | — | 1.6% | May 19, 2006 |
20Monitor | CVE-2005-1996No exploit | PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via bitrix · bitrix site manager · CWE-94 | Medium5.0 | — | 1.5% | Jun 15, 2005 |
20Monitor | CVE-2005-1995No exploit | Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_ebitrix · bitrix site manager | Medium5.0 | — | 1.4% | Jun 15, 2005 |
19Monitor | CVE-2006-2477No exploit | Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitrabitrix · bitrix site manager | Medium4.9 | — | 1.2% | May 19, 2006 |
- CVE-2015-835838Monitor
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execut
CriticalCVSS 9.0Proof of conceptEPSS 7%bitrix · mpbuilderDec 16, 2015
- CVE-2013-678830Monitor
The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it eas
HighCVSS 7.5No exploitEPSS 2%bitrix · bitrix e-store moduleMay 30, 2014
- CVE-2015-835729Monitor
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary f
MediumCVSS 6.5Proof of conceptEPSS 8%bitrix · xscanDec 16, 2015
- CVE-2020-1375824Monitor
modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by
MediumCVSS 6.1No exploitEPSS 1%bitrix · bitrix24Jun 1, 2020
- CVE-2006-247621Monitor
Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to
MediumCVSS 5.0No exploitEPSS 2%bitrix · bitrix site managerMay 19, 2006
- CVE-2006-247921Monitor
The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers
MediumCVSS 5.0No exploitEPSS 2%bitrix · bitrix site managerMay 19, 2006
- CVE-2006-247820Monitor
Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request.
MediumCVSS 5.0No exploitEPSS 2%bitrix · bitrix site managerMay 19, 2006
- CVE-2005-199620Monitor
PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via
MediumCVSS 5.0No exploitEPSS 2%bitrix · bitrix site managerJun 15, 2005
- CVE-2005-199520Monitor
Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_e
MediumCVSS 5.0No exploitEPSS 1%bitrix · bitrix site managerJun 15, 2005
- CVE-2006-247719Monitor
Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitra
MediumCVSS 4.9No exploitEPSS 1%bitrix · bitrix site managerMay 19, 2006