PT-2005-2941 · Bitrix+1 · Bitrix Site Manager+1

D_Bug

·

Publicado

2005-06-15

·

Atualizado

2017-07-11

·

CVE-2005-1995

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bitrix Site Manager versions 4.0.x
Description The issue allows remote attackers to obtain sensitive information by making a direct request to certain files. Specifically, requests to "subscr form.php" or "dbquery error.php" can reveal the path in an error message.
Recommendations For versions 4.0.x, consider restricting access to the "subscr form.php" and "dbquery error.php" files to minimize the risk of exploitation. As a temporary workaround, disabling error messages that reveal sensitive information can also help mitigate the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1995

Produtos afetados

Bitrix
Bitrix Site Manager