Bitrix kayıtları
bitrix üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2015-8358Kavram kanıtı | Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and executbitrix · mpbuilder · CWE-22 | Kritik9,0 | — | %6,6 | 16 Ara 2015 |
30İzleyin | CVE-2013-6788İstismar yok | The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easbitrix · bitrix e-store module · CWE-287 | Yüksek7,5 | — | %1,6 | 30 May 2014 |
29İzleyin | CVE-2015-8357Kavram kanıtı | Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary fbitrix · xscan · CWE-22 | Orta6,5 | — | %8,4 | 16 Ara 2015 |
24İzleyin | CVE-2020-13758İstismar yok | modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by bitrix · bitrix24 · CWE-79 | Orta6,1 | — | %0,9 | 1 Haz 2020 |
21İzleyin | CVE-2006-2476İstismar yok | Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to bitrix · bitrix site manager | Orta5,0 | — | %2,2 | 19 May 2006 |
21İzleyin | CVE-2006-2479İstismar yok | The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers bitrix · bitrix site manager | Orta5,0 | — | %1,9 | 19 May 2006 |
20İzleyin | CVE-2006-2478İstismar yok | Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request.bitrix · bitrix site manager | Orta5,0 | — | %1,6 | 19 May 2006 |
20İzleyin | CVE-2005-1996İstismar yok | PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via bitrix · bitrix site manager · CWE-94 | Orta5,0 | — | %1,5 | 15 Haz 2005 |
20İzleyin | CVE-2005-1995İstismar yok | Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_ebitrix · bitrix site manager | Orta5,0 | — | %1,4 | 15 Haz 2005 |
19İzleyin | CVE-2006-2477İstismar yok | Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitrabitrix · bitrix site manager | Orta4,9 | — | %1,2 | 19 May 2006 |
- CVE-2015-835838İzleyin
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execut
KritikCVSS 9,0Kavram kanıtıEPSS %7bitrix · mpbuilder16 Ara 2015
- CVE-2013-678830İzleyin
The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it eas
YüksekCVSS 7,5İstismar yokEPSS %2bitrix · bitrix e-store module30 May 2014
- CVE-2015-835729İzleyin
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary f
OrtaCVSS 6,5Kavram kanıtıEPSS %8bitrix · xscan16 Ara 2015
- CVE-2020-1375824İzleyin
modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by
OrtaCVSS 6,1İstismar yokEPSS %1bitrix · bitrix241 Haz 2020
- CVE-2006-247621İzleyin
Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to
OrtaCVSS 5,0İstismar yokEPSS %2bitrix · bitrix site manager19 May 2006
- CVE-2006-247921İzleyin
The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers
OrtaCVSS 5,0İstismar yokEPSS %2bitrix · bitrix site manager19 May 2006
- CVE-2006-247820İzleyin
Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request.
OrtaCVSS 5,0İstismar yokEPSS %2bitrix · bitrix site manager19 May 2006
- CVE-2005-199620İzleyin
PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via
OrtaCVSS 5,0İstismar yokEPSS %2bitrix · bitrix site manager15 Haz 2005
- CVE-2005-199520İzleyin
Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_e
OrtaCVSS 5,0İstismar yokEPSS %1bitrix · bitrix site manager15 Haz 2005
- CVE-2006-247719İzleyin
Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitra
OrtaCVSS 4,9İstismar yokEPSS %1bitrix · bitrix site manager19 May 2006