CVE-2005-1995: Bitrix Site Manager

Medium severity, CVSS 5.0. EPSS: 1.4% chance of exploitation in the next 30 days.

Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_error.php, which reveals the path in an error message.

Affected products

  • Bitrix Bitrix Site Manager: version 4.0.0 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; version 4.0.5 only; version 4.0.6 only; …

Published 2005-06-15. Last modified 2026-06-16.