« Volver al listado

CVE-2006-2478

Estado: ModificadaMedia (5)—

Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request. NOTE: this issue has been referred to as "cross-site scripting," but that is inconsistent with the common use of the term.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-2478",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-05-19T17:02:00.000",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0443.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/20143",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/918",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1016121",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/25625",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/434367/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/1858",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/26543",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0443.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/20143",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/918",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1016121",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/25625",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/434367/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/1858",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/26543",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request. NOTE: this issue has been referred to as \"cross-site scripting,\" but that is inconsistent with the common use of the term."
    }
  ],
  "lastModified": "2026-06-16T22:25:05.717",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:bitrix:bitrix_site_manager:4.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C8FAB07-B0A4-499E-A9F9-5135ED70FAB9"
            },
            {
              "criteria": "cpe:2.3:a:bitrix:bitrix_site_manager:4.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "964A32F7-699D-4096-8AF7-CDB6EBCA8FAE"
            },
            {
              "criteria": "cpe:2.3:a:bitrix:bitrix_site_manager:4.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02A233BC-68DA-4988-A840-B26B40294D44"
            },
            {
              "criteria": "cpe:2.3:a:bitrix:bitrix_site_manager:4.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EE66137-DED6-4EF3-90BC-29331C9281C8"
            },
            {
              "criteria": "cpe:2.3:a:bitrix:bitrix_site_manager:4.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C04D4F3-1E3D-436A-A8CF-F362DC854733"
            },
            {
              "criteria": "cpe:2.3:a:bitrix:bitrix_site_manager:4.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD84101B-84E9-44C5-9E5A-BEE676F12427"
            },
            {
              "criteria": "cpe:2.3:a:bitrix:bitrix_site_manager:4.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "704A4DF4-871F-4E20-9AA1-2725BC1CDB50"
            },
            {
              "criteria": "cpe:2.3:a:bitrix:bitrix_site_manager:4.0.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D469F51-611B-47F1-A5AC-4CE99E944DFB"
            },
            {
              "criteria": "cpe:2.3:a:bitrix:bitrix_site_manager:4.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37A63D71-42EF-4E05-A891-AB711F3309CC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}