CVE-2005-1996: Code Injection
Published Jun 15, 2005
·Updated
PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the SERVER[DOCUMENTROOT] parameter.
Affected Software
8 affected components
Bitrix Bitrix Site Manager=4.0.7
Bitrix Bitrix Site Manager=4.0.3
Bitrix Bitrix Site Manager=4.0.4
Bitrix Bitrix Site Manager=4.0.2
Bitrix Bitrix Site Manager=4.0.6
Bitrix Bitrix Site Manager=4.0.8
Bitrix Bitrix Site Manager=4.0.5
Bitrix Bitrix Site Manager=4.0.0
Remediation
Patch Available
Patch Available
Event History
Jun 15, 2005
CVE Published
04:00 AM
Jun 20, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1996?
CVE-2005-1996 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2005-1996?
To fix CVE-2005-1996, upgrade Bitrix Site Manager to a version that is not affected by this vulnerability, ideally 4.0.9 or later.
3
What versions of Bitrix Site Manager are affected by CVE-2005-1996?
CVE-2005-1996 affects Bitrix Site Manager versions 4.0.0 through 4.0.8.
4
What type of attack is possible with CVE-2005-1996?
CVE-2005-1996 allows remote attackers to execute arbitrary PHP code on the server.
5
Is there a workaround for CVE-2005-1996 if I cannot update Bitrix Site Manager?
While the best solution is to update, temporarily restricting file inclusion or disabling the affected features could mitigate the risk of exploitation.