CVE Vulnerabilities

CVE-2006-2476

Published: May 19, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

Affected Software

Name Vendor Start Version End Version
Bitrix_site_manager Bitrix * 4.1.0 (including)
Bitrix_site_manager Bitrix 4.0.0 (including) 4.0.0 (including)
Bitrix_site_manager Bitrix 4.0.2 (including) 4.0.2 (including)
Bitrix_site_manager Bitrix 4.0.3 (including) 4.0.3 (including)
Bitrix_site_manager Bitrix 4.0.4 (including) 4.0.4 (including)
Bitrix_site_manager Bitrix 4.0.5 (including) 4.0.5 (including)
Bitrix_site_manager Bitrix 4.0.6 (including) 4.0.6 (including)
Bitrix_site_manager Bitrix 4.0.7 (including) 4.0.7 (including)
Bitrix_site_manager Bitrix 4.0.8 (including) 4.0.8 (including)

References