Unrated severityNVD Advisory· Published Jun 15, 2005· Updated Apr 16, 2026
CVE-2005-1996
CVE-2005-1996
Description
PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMENT_ROOT] parameter.
Affected products
8cpe:2.3:a:bitrix:bitrix_site_manager:4.0.0:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:bitrix:bitrix_site_manager:4.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:bitrix:bitrix_site_manager:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:bitrix:bitrix_site_manager:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:bitrix:bitrix_site_manager:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:bitrix:bitrix_site_manager:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:bitrix:bitrix_site_manager:4.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:bitrix:bitrix_site_manager:4.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:bitrix:bitrix_site_manager:4.0.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/15726nvdPatchVendor Advisory
- www.bitrixsoft.com/sitemanager/versions.phpnvdPatch
- www.bitrixsoft.com/support/forum/read.phpnvdPatch
- www.osvdb.org/17341nvdPatch
- www.vupen.com/english/advisories/2005/0779nvdVendor Advisory
- marc.infonvd
- www.securityfocus.com/bid/13965nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/21018nvd
News mentions
0No linked articles in our index yet.