PT-2005-2941 · Bitrix+1 · Bitrix Site Manager+1

D_Bug

·

Published

2005-06-15

·

Updated

2017-07-11

·

CVE-2005-1995

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bitrix Site Manager versions 4.0.x
Description The issue allows remote attackers to obtain sensitive information by making a direct request to certain files. Specifically, requests to "subscr form.php" or "dbquery error.php" can reveal the path in an error message.
Recommendations For versions 4.0.x, consider restricting access to the "subscr form.php" and "dbquery error.php" files to minimize the risk of exploitation. As a temporary workaround, disabling error messages that reveal sensitive information can also help mitigate the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1995

Affected Products

Bitrix
Bitrix Site Manager