VendorsBitrixbitrix_site_managerany version
Vulnerabilities

Bitrix Bitrix Site Manager any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2013-6788
The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for remote attackers to guess the cookie value and bypass authentication via a brute force attack.
Published 2014-05-30 · Modified
7.5EPSS 0.016
CVE-2006-2476
Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.
Published 2006-05-19 · Modified
5.0EPSS 0.022