CVE-2015-8357 Information
Feb 14, 2021
cve
Description
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary files and consequently obtain sensitive information or cause a denial of service via a .. (dot dot) in the file parameter to admin/bitrix.xscan_worker.php.
Reference
http://packetstormsecurity.com/files/134765/bitrix.scan-Bitrix-1.0.3-Path-Traversal.html http://www.securityfocus.com/archive/1/537072/100/0/threaded https://marketplace.1c-bitrix.ru/solutions/bitrix.xscan/tab-log-link https://www.exploit-db.com/exploits/38976/ https://www.htbridge.com/advisory/HTB23278
Share on: