CVE Vulnerabilities

CVE-2006-2476

Published: May 19, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

Affected Software

NameVendorStart VersionEnd Version
Bitrix_site_managerBitrix*4.1.0 (including)
Bitrix_site_managerBitrix4.0.0 (including)4.0.0 (including)
Bitrix_site_managerBitrix4.0.2 (including)4.0.2 (including)
Bitrix_site_managerBitrix4.0.3 (including)4.0.3 (including)
Bitrix_site_managerBitrix4.0.4 (including)4.0.4 (including)
Bitrix_site_managerBitrix4.0.5 (including)4.0.5 (including)
Bitrix_site_managerBitrix4.0.6 (including)4.0.6 (including)
Bitrix_site_managerBitrix4.0.7 (including)4.0.7 (including)
Bitrix_site_managerBitrix4.0.8 (including)4.0.8 (including)

References