6.5
CVSSv2

CVE-2015-8357

Published: 16/12/2015 Updated: 09/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in the bitrix.xscan module prior to 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary files, and consequently obtain sensitive information or cause a denial of service, via a .. (dot dot) in the file parameter to admin/bitrix.xscan_worker.php.

Vulnerable Product Search on Vulmon Subscribe to Product

bitrix xscan

Exploits

Advisory ID: HTB23278 Product: bitrixxscan Bitrix module Vendor: Bitrix Vulnerable Version(s): 103 and probably prior Tested Version: 103 Advisory Publication: November 18, 2015 [without technical details] Vendor Notification: November 18, 2015 Vendor Patch: November 24, 2015 Public Disclosure: December 9, 2015 Vulnerability Type: Path Tr ...
bitrixscan Bitrix module version 103 suffers from a path traversal vulnerability ...