Записи Bitrix
10 опубликованных записей вендора bitrix.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
38Наблюдать | CVE-2015-8358Proof of concept | Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and executbitrix · mpbuilder · CWE-22 | Критическая9,0 | — | 6,6 % | 16 дек. 2015 г. |
30Наблюдать | CVE-2013-6788Эксплойта нет | The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easbitrix · bitrix e-store module · CWE-287 | Высокая7,5 | — | 1,6 % | 30 мая 2014 г. |
29Наблюдать | CVE-2015-8357Proof of concept | Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary fbitrix · xscan · CWE-22 | Средняя6,5 | — | 8,4 % | 16 дек. 2015 г. |
24Наблюдать | CVE-2020-13758Эксплойта нет | modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by bitrix · bitrix24 · CWE-79 | Средняя6,1 | — | 0,9 % | 1 июн. 2020 г. |
21Наблюдать | CVE-2006-2476Эксплойта нет | Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to bitrix · bitrix site manager | Средняя5,0 | — | 2,2 % | 19 мая 2006 г. |
21Наблюдать | CVE-2006-2479Эксплойта нет | The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers bitrix · bitrix site manager | Средняя5,0 | — | 1,9 % | 19 мая 2006 г. |
20Наблюдать | CVE-2006-2478Эксплойта нет | Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request.bitrix · bitrix site manager | Средняя5,0 | — | 1,6 % | 19 мая 2006 г. |
20Наблюдать | CVE-2005-1996Эксплойта нет | PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via bitrix · bitrix site manager · CWE-94 | Средняя5,0 | — | 1,5 % | 15 июн. 2005 г. |
20Наблюдать | CVE-2005-1995Эксплойта нет | Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_ebitrix · bitrix site manager | Средняя5,0 | — | 1,4 % | 15 июн. 2005 г. |
19Наблюдать | CVE-2006-2477Эксплойта нет | Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitrabitrix · bitrix site manager | Средняя4,9 | — | 1,2 % | 19 мая 2006 г. |
- CVE-2015-835838Наблюдать
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execut
КритическаяCVSS 9,0Proof of conceptEPSS 7 %bitrix · mpbuilder16 дек. 2015 г.
- CVE-2013-678830Наблюдать
The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it eas
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bitrix · bitrix e-store module30 мая 2014 г.
- CVE-2015-835729Наблюдать
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary f
СредняяCVSS 6,5Proof of conceptEPSS 8 %bitrix · xscan16 дек. 2015 г.
- CVE-2020-1375824Наблюдать
modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by
СредняяCVSS 6,1Эксплойта нетEPSS 1 %bitrix · bitrix241 июн. 2020 г.
- CVE-2006-247621Наблюдать
Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to
СредняяCVSS 5,0Эксплойта нетEPSS 2 %bitrix · bitrix site manager19 мая 2006 г.
- CVE-2006-247921Наблюдать
The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers
СредняяCVSS 5,0Эксплойта нетEPSS 2 %bitrix · bitrix site manager19 мая 2006 г.
- CVE-2006-247820Наблюдать
Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request.
СредняяCVSS 5,0Эксплойта нетEPSS 2 %bitrix · bitrix site manager19 мая 2006 г.
- CVE-2005-199620Наблюдать
PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via
СредняяCVSS 5,0Эксплойта нетEPSS 2 %bitrix · bitrix site manager15 июн. 2005 г.
- CVE-2005-199520Наблюдать
Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_e
СредняяCVSS 5,0Эксплойта нетEPSS 1 %bitrix · bitrix site manager15 июн. 2005 г.
- CVE-2006-247719Наблюдать
Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitra
СредняяCVSS 4,9Эксплойта нетEPSS 1 %bitrix · bitrix site manager19 мая 2006 г.