PT-2005-2941 · Bitrix+1 · Bitrix Site Manager+1
D_Bug
·
Publicado
2005-06-15
·
Atualizado
2017-07-11
·
CVE-2005-1995
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Bitrix Site Manager versions 4.0.x
Description
The issue allows remote attackers to obtain sensitive information by making a direct request to certain files. Specifically, requests to "subscr form.php" or "dbquery error.php" can reveal the path in an error message.
Recommendations
For versions 4.0.x, consider restricting access to the "subscr form.php" and "dbquery error.php" files to minimize the risk of exploitation. As a temporary workaround, disabling error messages that reveal sensitive information can also help mitigate the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bitrix
Bitrix Site Manager