Перейти к содержимому
Noroxi

Записи Bitrix

10 опубликованных записей вендора bitrix.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 20

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

10 записей
  • CVE-2015-8358
    38Наблюдать

    Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execut

    КритическаяCVSS 9,0Proof of conceptEPSS 7 %

    bitrix · mpbuilder16 дек. 2015 г.

  • CVE-2013-6788
    30Наблюдать

    The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it eas

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    bitrix · bitrix e-store module30 мая 2014 г.

  • CVE-2015-8357
    29Наблюдать

    Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary f

    СредняяCVSS 6,5Proof of conceptEPSS 8 %

    bitrix · xscan16 дек. 2015 г.

  • CVE-2020-13758
    24Наблюдать

    modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    bitrix · bitrix241 июн. 2020 г.

  • CVE-2006-2476
    21Наблюдать

    Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    bitrix · bitrix site manager19 мая 2006 г.

  • CVE-2006-2479
    21Наблюдать

    The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    bitrix · bitrix site manager19 мая 2006 г.

  • CVE-2006-2478
    20Наблюдать

    Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request.

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    bitrix · bitrix site manager19 мая 2006 г.

  • CVE-2005-1996
    20Наблюдать

    PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    bitrix · bitrix site manager15 июн. 2005 г.

  • CVE-2005-1995
    20Наблюдать

    Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_e

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    bitrix · bitrix site manager15 июн. 2005 г.

  • CVE-2006-2477
    19Наблюдать

    Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitra

    СредняяCVSS 4,9Эксплойта нетEPSS 1 %

    bitrix · bitrix site manager19 мая 2006 г.