PT-2006-3427 · Bitrix+1 · Bitrix Site Manager+1

Gogi The Georgian

·

Publicado

2006-05-19

·

Atualizado

2018-10-18

·

CVE-2006-2479

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Bitrix Site Manager versions 4.1.x
Description The issue concerns the Update functionality, which fails to verify the authenticity of downloaded updates. This allows remote attackers to obtain sensitive information and execute arbitrary PHP code via DNS cache poisoning, redirecting the user to a malicious site.
Recommendations For Bitrix Site Manager versions 4.1.x, consider implementing authentication checks for downloaded updates to prevent DNS cache poisoning attacks. As a temporary workaround, restrict access to the update functionality until a proper fix is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2479

Produtos afetados

Bitrix
Bitrix Site Manager