Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bitrix24 MEDIUM 6.1
CVE-2020-13758

modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by placing %…

Fix: after 20.0.950
Fix from $1,600 2020-06-01
Mpbuilder HIGH 9.0
CVE-2015-8358EPSS 7%

Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execute arbitra…

Fix: after 1.0.11
Fix from $1,950 2015-12-16
Xscan MEDIUM 6.5
CVE-2015-8357EPSS 8%

Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary files, and…

Fix: after 1.0.3
Fix from $1,600 2015-12-16
Bitrix E Store Module HIGH 7.5
CVE-2013-6788

The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for r…

Fix: after 14.0.0
Fix from $1,950 2014-05-30
Bitrix Site Manager MEDIUM 5.0
CVE-2006-2476

Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain se…

Fix: after 4.1.0
Fix from $1,600 2006-05-19
Bitrix Site Manager MEDIUM 5.0
CVE-2006-2478

Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request. NOTE: this …

No fix yet
Fix from $1,600 2006-05-19
Bitrix Site Manager MEDIUM 5.0
CVE-2006-2479

The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers to obtain…

No fix yet
Fix from $1,600 2006-05-19
Bitrix Site Manager MEDIUM 5.0
CVE-2005-1995

Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_error.php,…

Patch available
Fix from $1,600 2005-06-15
Bitrix Site Manager MEDIUM 5.0
CVE-2005-1996

PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERV…

Patch available
Fix from $1,600 2005-06-15