CVE-2006-2477: XSS
Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitrary web script or HTML via unspecified inputs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2477?
CVE-2006-2477 is considered a critical Cross-site scripting (XSS) vulnerability that can allow attackers to execute arbitrary web scripts or HTML.
How do I fix CVE-2006-2477?
To fix CVE-2006-2477, update the Bitrix Site Manager to a version that has patched this XSS vulnerability.
What versions of Bitrix Site Manager are affected by CVE-2006-2477?
CVE-2006-2477 affects Bitrix Site Manager versions 4.0.0 to 4.1.0, specifically versions 4.0.0, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7, 4.0.8, and 4.1.0.
What type of vulnerability is CVE-2006-2477?
CVE-2006-2477 is categorized as a Cross-site scripting (XSS) vulnerability.
Can CVE-2006-2477 affect user data?
Yes, CVE-2006-2477 can potentially compromise user data by allowing attackers to inject malicious scripts that can manipulate or steal sensitive information.