CVE-2005-1995: Medium severity bitrix bitrix site manager vulnerability
Published Jun 15, 2005
·Updated
Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscrform.php or (2) dbqueryerror.php, which reveals the path in an error message.
Affected Software
8 affected components
Bitrix Bitrix Site Manager=4.0.0
Bitrix Bitrix Site Manager=4.0.2
Bitrix Bitrix Site Manager=4.0.3
Bitrix Bitrix Site Manager=4.0.4
Bitrix Bitrix Site Manager=4.0.5
Bitrix Bitrix Site Manager=4.0.6
Bitrix Bitrix Site Manager=4.0.7
Bitrix Bitrix Site Manager=4.0.8
Event History
Jun 15, 2005
CVE Published
04:00 AM
Jun 20, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1995?
CVE-2005-1995 is classified as a medium severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2005-1995?
To mitigate CVE-2005-1995, update your Bitrix Site Manager software to a secure version that is not affected.
3
What versions are affected by CVE-2005-1995?
CVE-2005-1995 affects Bitrix Site Manager versions 4.0.0 to 4.0.8.
4
What does CVE-2005-1995 exploit?
CVE-2005-1995 allows remote attackers to exploit sensitive information disclosure through direct requests to specific PHP files.
5
Is there a workaround for CVE-2005-1995?
A temporary workaround for CVE-2005-1995 is to restrict access to the affected PHP files to authorized users only.