CVE-2006-2479

The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers to obtain sensitive information and ultimately execute arbitrary PHP code via DNS cache poisoning that redirects the user to a malicious site.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bitrix:bitrix_site_manager:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:bitrix:bitrix_site_manager:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:bitrix:bitrix_site_manager:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:bitrix:bitrix_site_manager:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:bitrix:bitrix_site_manager:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:bitrix:bitrix_site_manager:4.0.6:*:*:*:*:*:*:*
cpe:2.3:a:bitrix:bitrix_site_manager:4.0.7:*:*:*:*:*:*:*
cpe:2.3:a:bitrix:bitrix_site_manager:4.0.8:*:*:*:*:*:*:*
cpe:2.3:a:bitrix:bitrix_site_manager:4.1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:11

Type Values Removed Values Added
References () http://securityreason.com/securityalert/918 - () http://securityreason.com/securityalert/918 -
References () http://securitytracker.com/id?1016121 - Exploit () http://securitytracker.com/id?1016121 - Exploit
References () http://www.securityfocus.com/archive/1/434367/100/0/threaded - () http://www.securityfocus.com/archive/1/434367/100/0/threaded -
References () http://www.vupen.com/english/advisories/2006/1858 - () http://www.vupen.com/english/advisories/2006/1858 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/26542 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/26542 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/26548 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/26548 -

Information

Published : 2006-05-19 17:02

Updated : 2024-11-21 00:11


NVD link : CVE-2006-2479

Mitre link : CVE-2006-2479

CVE.ORG link : CVE-2006-2479


JSON object : View

Products Affected

bitrix

  • bitrix_site_manager