Report

Version: 0.15.1
Scan date: 2026-05-16 02:06:15
Files analyzed: 33206 | Files infected: 197

/var/www/pavrusru/data/www/pavrus.ru/bitrix/index.php

Size: 83.00 B Created: 2018-02-28 10:31:52 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Sign 0f37c730 Line: 2 Dangerous

Malware Signature (hash: 0f37c730)

meta http-equiv="REFRESH" content="0;

/var/www/pavrusru/data/www/pavrus.ru/bitrix/admin/cat_section_admin.php

Size: 129.00 B Created: 2018-02-28 10:38:40 Modified: 2026-05-12 15:55:48 Dangers: 1
DescriptionMatch

Exploit execution Line: 3 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"]."/bitrix/modules/iblock/admin/iblock_section_admin.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/admin/cat_product_edit.php

Size: 128.00 B Created: 2018-02-28 10:38:36 Modified: 2026-05-12 15:55:48 Dangers: 1
DescriptionMatch

Exploit execution Line: 3 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"]."/bitrix/modules/iblock/admin/iblock_element_edit.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/admin/cat_product_admin.php

Size: 129.00 B Created: 2018-02-28 10:38:40 Modified: 2026-05-12 15:55:48 Dangers: 1
DescriptionMatch

Exploit execution Line: 3 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"]."/bitrix/modules/iblock/admin/iblock_element_admin.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/admin/cat_product_list.php

Size: 126.00 B Created: 2018-02-28 10:38:38 Modified: 2026-05-12 15:55:48 Dangers: 1
DescriptionMatch

Exploit execution Line: 3 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"]."/bitrix/modules/iblock/admin/iblock_list_admin.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/admin/cat_section_edit.php

Size: 128.00 B Created: 2018-02-28 10:38:38 Modified: 2026-05-12 15:55:48 Dangers: 1
DescriptionMatch

Exploit execution Line: 3 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"]."/bitrix/modules/iblock/admin/iblock_section_edit.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/php_interface/include/catalog_export/cron_frame.php

Size: 3.43 kB Created: 2018-02-28 10:33:44 Modified: 2026-05-12 15:55:57 Dangers: 1
DescriptionMatch

Exploit execution Line: 93 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$strFile)

/var/www/pavrusru/data/www/pavrus.ru/bitrix/php_interface/include/catalog_import/cron_frame.php

Size: 3.51 kB Created: 2018-02-28 10:33:44 Modified: 2026-05-12 15:55:57 Dangers: 1
DescriptionMatch

Exploit execution Line: 96 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$strFile)

/var/www/pavrusru/data/www/pavrus.ru/bitrix/gadgets/bitrix/weather/.description.php

Size: 143.00 B Created: 2018-02-28 10:38:36 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Exploit execution Line: 2 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER['DOCUMENT_ROOT'].'/bitrix/gadgets/bitrix/weather/lang/ru/exec/.description.php')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/gadgets/bitrix/weather/index.php

Size: 99.00 B Created: 2018-02-28 10:38:36 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Exploit execution Line: 2 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER['DOCUMENT_ROOT'].'/bitrix/gadgets/bitrix/weather/lang/ru/exec/index.php')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/gadgets/bitrix/weather/.parameters.php

Size: 103.00 B Created: 2018-02-28 10:38:36 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Exploit execution Line: 2 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER['DOCUMENT_ROOT'].'/bitrix/gadgets/bitrix/weather/lang/ru/exec/.parameters.php')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/gadgets/bitrix/admin_security/index.php

Size: 4.56 kB Created: 2023-01-31 12:50:43 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Exploit execution Line: 41 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"]."/bitrix/modules/security/install/version.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/gadgets/bitrix/probki/.description.php

Size: 142.00 B Created: 2018-02-28 10:38:36 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Exploit execution Line: 2 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER['DOCUMENT_ROOT'].'/bitrix/gadgets/bitrix/probki/lang/ru/exec/.description.php')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/gadgets/bitrix/probki/index.php

Size: 98.00 B Created: 2018-02-28 10:38:36 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Exploit execution Line: 2 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER['DOCUMENT_ROOT'].'/bitrix/gadgets/bitrix/probki/lang/ru/exec/index.php')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/gadgets/bitrix/probki/.parameters.php

Size: 102.00 B Created: 2018-02-28 10:38:36 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Exploit execution Line: 2 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER['DOCUMENT_ROOT'].'/bitrix/gadgets/bitrix/probki/lang/ru/exec/.parameters.php')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/gadgets/bitrix/admin_info/index.php

Size: 2.18 kB Created: 2026-05-14 17:05:21 Modified: 2026-05-14 17:05:21 Dangers: 1
DescriptionMatch

Exploit execution Line: 6 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].BX_ROOT."/.config.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/main.numerator.edit/templates/admin/template.php

Size: 572.00 B Created: 2026-05-14 17:02:29 Modified: 2026-05-14 17:02:29 Dangers: 1
DescriptionMatch

Exploit execution Line: 21 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"] . $this->GetFolder()

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.store/templates/.default/style.css

Size: 873.00 B Created: 2018-02-28 10:31:41 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Table*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.store/templates/bootstrap_v4/style.css

Size: 873.00 B Created: 2023-01-28 01:59:55 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Table*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.personal.cc.list/templates/.default/style.css

Size: 448.00 B Created: 2018-02-28 10:31:22 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Table*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/landing.mainpage.pub/templates/.default/style-widgets.css

Size: 1.25 MB Created: 2026-05-15 23:23:12 Modified: 2026-05-15 23:23:12 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 46615 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*EVENT*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/b24connector.button.list/ajax.php

Size: 3.73 kB Created: 2018-02-28 10:30:36 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Function exec Warning

Potentially dangerous function `exec`

[https://www.php.net/exec]

exec() { $this->request Context::getCurrent()->getRequest(); $this->action $this->request->get('action'); $this->prepareRequestData(); if($this->check()) { call_user_func_array($this->getActionCall(), array($this->requestData)); } $this->giveResponse(); } } $controller = new B24CButtonListAjaxController(); $controller->exec()

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/menu/templates/tree/style.css

Size: 851.00 B Created: 2018-02-28 10:31:41 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 43 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Icons*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/menu/templates/horizontal_multilevel/style.css

Size: 4.31 kB Created: 2018-02-28 10:31:41 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 19 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.basket.basket.small.mail/templates/.default/style.css

Size: 329.00 B Created: 2018-02-28 10:31:12 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Table*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.location.import/templates/admin/style.css

Size: 2.12 kB Created: 2018-02-28 10:31:23 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Sign 7830f7a6 Line: 61 Dangerous

Malware Signature (hash: 7830f7a6)

nc-l

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.location.import/templates/admin/template.php

Size: 14.05 kB Created: 2026-05-15 23:21:13 Modified: 2026-05-15 23:21:13 Dangers: 1
DescriptionMatch

Sign 7830f7a6 Line: 24 Dangerous

Malware Signature (hash: 7830f7a6)

nc-l

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.location.import/templates/admin/style.min.css

Size: 1.88 kB Created: 2018-02-28 10:31:23 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Sign 7830f7a6 Line: 1 Dangerous

Malware Signature (hash: 7830f7a6)

nc-l

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/forum.rules/lang/en/component.php

Size: 4.71 kB Created: 2018-02-28 10:31:52 Modified: 2026-05-12 15:55:49 Dangers: 1
DescriptionMatch

Sign 407651f7 Line: 27 Dangerous

Malware Signature (hash: 407651f7)

warez

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/forum.rules/lang/de/component.php

Size: 5.15 kB Created: 2026-05-14 16:58:26 Modified: 2026-05-14 16:58:26 Dangers: 1
DescriptionMatch

Sign 407651f7 Line: 23 Dangerous

Malware Signature (hash: 407651f7)

Warez

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.item/templates/.default/style.css

Size: 24.90 kB Created: 2026-05-14 16:58:40 Modified: 2026-05-14 16:58:40 Warns: 5
DescriptionMatch

Exploit infected_comment Line: 236 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Label*/

Exploit infected_comment Line: 268 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*SMALL*/

Exploit infected_comment Line: 416 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Title*/

Exploit infected_comment Line: 440 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Price*/

Exploit infected_comment Line: 67 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Image*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.item/templates/bootstrap_v4/style.css

Size: 26.00 kB Created: 2026-05-14 16:58:40 Modified: 2026-05-14 16:58:40 Warns: 5
DescriptionMatch

Exploit infected_comment Line: 258 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Label*/

Exploit infected_comment Line: 290 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*SMALL*/

Exploit infected_comment Line: 442 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Title*/

Exploit infected_comment Line: 485 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Price*/

Exploit infected_comment Line: 83 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Image*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.filter/component.php

Size: 32.92 kB Created: 2023-01-31 12:43:58 Modified: 2026-05-12 15:55:49 Warns: 2
DescriptionMatch

Exploit double_var2 Line: 70 Warning

Double var technique is usually used for the obfuscation of malicious code

${$FILTER_NAME}

Exploit double_var2 Line: 73 Warning

Double var technique is usually used for the obfuscation of malicious code

${$PREFILTER_NAME}

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog.post.comment/templates/.default/template.php

Size: 30.03 kB Created: 2023-01-31 12:39:34 Modified: 2026-05-12 15:55:49 Dangers: 3
DescriptionMatch

Exploit execution Line: 134 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/neweditor.php")

Exploit execution Line: 23 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/script.php")

Exploit execution Line: 24 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/scripts_for_editor.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog.post.comment/templates/.default/scripts_for_editor.php

Size: 15.25 kB Created: 2018-06-26 15:08:10 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Function eval Warning

Potentially dangerous function `eval`

[https://www.php.net/eval]

eval(scripts[s].JS);
                        }
                    }
                    
                    
BX.ajax.processScripts(scriptstrue);
//                    commentEr object may be set in template
                    
if(window.commentEr && window.commentEr == "Y")
                    {
                        
BX('err_comment_'+this.id[1]).innerHTML data;
                    }
                    else
                    {
                        if(
BX('edit_id').value 0)
                        {
                            var 
commentId 'blg-comment-'+this.id[1];
                            if(
BX(commentId))
                            {
                                var 
newComment BX.create('div',{'html':data});    // tmp container for data
//                                paste resp...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/report.construct/templates/admin/template.php

Size: 40.07 kB Created: 2026-05-14 17:00:53 Modified: 2026-05-14 17:00:53 Warns: 1
DescriptionMatch

Function exec Warning

Potentially dangerous function `exec`

[https://www.php.net/exec]

exec(ySelects[i].name))
            {
                
colId = match[1];
                if (
colId !== null && yColumnsIndexes[colId] !== null)
                    
setSelectValue(ySelects[i], yColumnsIndexes[colId]);
            }
        }
        var 
chartCheckbox BX('report-chart-display-checkbox');
        if (
chartCheckbox)
        {
            
BX.bind(chartCheckbox'click', function () {
                var 
chartSwitchBlock BX('report-chart-switch');
                var 
chartParamsBlock BX('report-chart-params');
                if (
chartSwitchBlock)
                {
                    if (
this.checkedBX.addClass(chartSwitchBloc...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/report.construct/templates/.default/template.php

Size: 40.37 kB Created: 2026-05-14 17:00:53 Modified: 2026-05-14 17:00:53 Warns: 1
DescriptionMatch

Function exec Warning

Potentially dangerous function `exec`

[https://www.php.net/exec]

exec(ySelects[i].name))
            {
                
colId = match[1];
                if (
colId !== null && yColumnsIndexes[colId] !== null)
                    
setSelectValue(ySelects[i], yColumnsIndexes[colId]);
            }
        }
        var 
chartCheckbox BX('report-chart-display-checkbox');
        if (
chartCheckbox)
        {
            
BX.bind(chartCheckbox'click', function () {
                var 
chartSwitchBlock BX('report-chart-switch');
                var 
chartParamsBlock BX('report-chart-params');
                if (
chartSwitchBlock)
                {
                    if (
this.checkedBX.addClass(chartSwitchBloc...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.order.ajax/templates/.default/style.css

Size: 44.38 kB Created: 2023-01-31 12:51:01 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 1210 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*block*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.order.ajax/templates/bootstrap_v4/style.css

Size: 32.37 kB Created: 2023-01-31 12:51:01 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 1293 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*block*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.comments/templates/.default/bitrix/blog.post.comment/adapt/template.php

Size: 32.72 kB Created: 2026-05-15 23:21:25 Modified: 2026-05-15 23:21:25 Dangers: 3
DescriptionMatch

Exploit execution Line: 189 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/neweditor.php")

Exploit execution Line: 33 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/script.php")

Exploit execution Line: 34 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/scripts_for_editor.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.comments/templates/.default/bitrix/blog.post.comment/adapt/scripts_for_editor.php

Size: 14.80 kB Created: 2018-06-26 15:07:38 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Function eval Warning

Potentially dangerous function `eval`

[https://www.php.net/eval]

eval(scripts[s].JS);
                        }
                    }
                    
                    
BX.ajax.processScripts(scriptstrue);
//                    commentEr object may be set in template
                    
if(window.commentEr && window.commentEr == "Y")
                    {
                        
BX('err_comment_'+this.id[1]).innerHTML data;
                    }
                    else
                    {
                        if(
BX('edit_id').value 0)
                        {
                            var 
commentId 'blg-comment-'+this.id[1];
                            if(
BX(commentId))
                            {
                                var 
newComment BX.create('div',{'html':data});    // tmp container for data
//                                paste resp...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/photogallery.detail.list/templates/slider_big/template.php

Size: 16.21 kB Created: 2023-01-31 12:45:14 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Function eval Line: 337 Warning

Potentially dangerous function `eval`

[https://www.php.net/eval]

eval("div.onclick = function(e){jsUtils.PreventDefault(e); jsUtils.Redirect([], '" res[ii].href "');};");
        
res[ii].parentNode.insertBefore(divres[ii]);
        
res[ii].onmouseover = function()
        {
            
this.previousSibling.onshow();
            
this.bxMouseOver 'Y';
        };
        
res[ii].onmouseout = function()
        {
            
this.bxMouseOver 'N';
            var 
__this this;
            
setTimeout(
                function()
                {
                    if (
__this.previousSibling && __this.previousSibling.bxMouseOver != "Y")
                    {
                        
__this.previousSibling...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/photogallery_user/templates/.default/galleries_recalc.php

Size: 9.54 kB Created: 2026-05-14 16:59:40 Modified: 2026-05-14 16:59:40 Warns: 1
DescriptionMatch

Function eval Warning

Potentially dangerous function `eval`

[https://www.php.net/eval]

eval("var result = " data "; "); }
            if (
result['status'] == 'inprogress')
            {
                
document.getElementById('photogallery_recalc').innerHTML result['text'];
                if (
__this_source.bReady == false)
                {
                    
document.getElementById('ButtonPhotoGalleryRecalcStart').disabled false;
                    
document.getElementById('ButtonPhotoGalleryRecalcContinue').disabled false;
                    
document.getElementById('ButtonPhotoGalleryRecalcStop').disabled true;
                }
                else
                {
                    
document.getElementById(...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.element/templates/.default/style.css

Size: 24.48 kB Created: 2023-01-31 12:51:47 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 648 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Label*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.element/templates/.default/template.php

Size: 65.65 kB Created: 2026-05-15 23:21:24 Modified: 2026-05-15 23:21:24 Dangers: 1
DescriptionMatch

Exploit clever_include Line: 1167 Dangerous

LFI (Local File Inclusion), through a image inclusion, allow remote attackers to inject and execute arbitrary commands or code on the target machine

INCLUDE' => $arParams['PRICE_VAT_INCLUDE'],
                                '
CONVERT_CURRENCY' => $arParams['CONVERT_CURRENCY'],
                                '
BASKET_URL' => $arParams['BASKET_URL'],
                                '
ADD_PROPERTIES_TO_BASKET' => $arParams['ADD_PROPERTIES_TO_BASKET'],
                                '
PRODUCT_PROPS_VARIABLE' => $arParams['PRODUCT_PROPS_VARIABLE'],
                                '
PARTIAL_PRODUCT_PROPERTIES' => $arParams['PARTIAL_PRODUCT_PROPERTIES'],
                                '
USE_PRODUCT_QUANTITY' => 'N',
                                '
PRODUCT_QUANTITY_VARIABLE' => $arParams['PRODUCT_QUANTITY_VARIABLE'...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.element/templates/bootstrap_v4/template.php

Size: 65.81 kB Created: 2026-05-15 23:21:24 Modified: 2026-05-15 23:21:24 Dangers: 1
DescriptionMatch

Exploit clever_include Line: 1202 Dangerous

LFI (Local File Inclusion), through a image inclusion, allow remote attackers to inject and execute arbitrary commands or code on the target machine

INCLUDE' => $arParams['PRICE_VAT_INCLUDE'],
                        '
CONVERT_CURRENCY' => $arParams['CONVERT_CURRENCY'],
                        '
BASKET_URL' => $arParams['BASKET_URL'],
                        '
ADD_PROPERTIES_TO_BASKET' => $arParams['ADD_PROPERTIES_TO_BASKET'],
                        '
PRODUCT_PROPS_VARIABLE' => $arParams['PRODUCT_PROPS_VARIABLE'],
                        '
PARTIAL_PRODUCT_PROPERTIES' => $arParams['PARTIAL_PRODUCT_PROPERTIES'],
                        '
USE_PRODUCT_QUANTITY' => 'N',
                        '
PRODUCT_QUANTITY_VARIABLE' => $arParams['PRODUCT_QUANTITY_VARIABLE'],
                        '
CACH...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.element/templates/store_v3/template.php

Size: 68.07 kB Created: 2026-05-15 23:21:24 Modified: 2026-05-15 23:21:24 Dangers: 1
DescriptionMatch

Exploit clever_include Dangerous

LFI (Local File Inclusion), through a image inclusion, allow remote attackers to inject and execute arbitrary commands or code on the target machine

INCLUDE' => $arParams['PRICE_VAT_INCLUDE'], 'CONVERT_CURRENCY' => $arParams['CONVERT_CURRENCY'], 'BASKET_URL' => $arParams['BASKET_URL'], 'ADD_PROPERTIES_TO_BASKET' => $arParams['ADD_PROPERTIES_TO_BASKET'], 'PRODUCT_PROPS_VARIABLE' => $arParams['PRODUCT_PROPS_VARIABLE'], 'PARTIAL_PRODUCT_PROPERTIES' => $arParams['PARTIAL_PRODUCT_PROPERTIES'], 'USE_PRODUCT_QUANTITY' => 'N', 'PRODUCT_QUANTITY_VARIABLE' => $arParams['PRODUCT_QUANTITY_VARIABLE'], 'CACHE_GROUPS' => $arParams['CACHE_GROUPS'], 'POTENTI...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/photogallery/templates/.default/bitrix/blog.post.comment/photogallery/template.php

Size: 29.88 kB Created: 2023-01-31 12:39:40 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Exploit execution Line: 13 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/script.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.ajax.delivery.calculator/templates/.default/ajax.php

Size: 0.99 kB Created: 2018-02-28 10:31:51 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Sign 11413268 Line: 15 Dangerous

Malware Signature (hash: 11413268)

eval($_REQUEST

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.ajax.delivery.calculator/templates/input/ajax.php

Size: 864.00 B Created: 2018-02-28 10:31:51 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Sign 11413268 Line: 15 Dangerous

Malware Signature (hash: 11413268)

eval($_REQUEST

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/forum.index/class.php

Size: 16.86 kB Created: 2026-05-14 16:58:35 Modified: 2026-05-14 16:58:35 Warns: 1
DescriptionMatch

Exploit double_var2 Line: 233 Warning

Double var technique is usually used for the obfuscation of malicious code

${$PAGEN_NAME}

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sender.message.editor/templates/.default/template.php

Size: 15.15 kB Created: 2026-05-14 17:04:30 Modified: 2026-05-14 17:04:30 Dangers: 1
DescriptionMatch

Exploit nano Line: 212 Dangerous

Nano is a family of PHP webshells which are code golfed to be extremely stealthy and efficient

[https://github.com/s0md3v/nano]

$option['view']()

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/.default/themes/red2/style.css

Size: 1.14 kB Created: 2018-02-28 10:31:22 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/.default/themes/red/style.css

Size: 1.11 kB Created: 2018-02-28 10:31:22 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/.default/themes/green/style.css

Size: 1.11 kB Created: 2018-02-28 10:31:22 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/.default/themes/orange/style.css

Size: 1.11 kB Created: 2018-02-28 10:31:22 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/.default/themes/blue/style.css

Size: 1.10 kB Created: 2018-02-28 10:31:22 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/.default/style.css

Size: 32.99 kB Created: 2023-01-31 12:51:08 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 259 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/general_page/themes/red/style.css

Size: 1.11 kB Created: 2018-02-28 10:31:22 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/general_page/themes/green/style.css

Size: 1.11 kB Created: 2018-02-28 10:31:22 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/general_page/themes/blue/style.css

Size: 1.10 kB Created: 2018-02-28 10:31:22 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/general_page/style.css

Size: 26.93 kB Created: 2023-01-31 12:39:35 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 252 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/one_blog/style.css

Size: 31.01 kB Created: 2018-06-26 15:08:10 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 252 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/one_blog_old_version/bitrix/blog.post.comment/.default/template.php

Size: 21.48 kB Created: 2023-01-31 12:51:08 Modified: 2026-05-12 15:55:49 Dangers: 1
DescriptionMatch

Exploit execution Line: 8 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/script.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/one_blog_old_version/bitrix/blog.post.edit/.default/template.php

Size: 24.59 kB Created: 2026-05-14 16:59:26 Modified: 2026-05-14 16:59:26 Dangers: 1
DescriptionMatch

Exploit execution Line: 370 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/script.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/one_blog_with_main_page/bitrix/blog.post.comment/.default/template.php

Size: 21.26 kB Created: 2023-01-31 12:51:08 Modified: 2026-05-12 15:55:49 Dangers: 1
DescriptionMatch

Exploit execution Line: 8 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/script.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/one_blog_with_main_page/bitrix/blog.post.comment/.default/script.php

Size: 11.35 kB Created: 2018-02-28 10:31:20 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Function eval Warning

Potentially dangerous function `eval`

[https://www.php.net/eval]

eval(thetag "_open");

    if (
tagOpen == 0)
    {
        if (
doInsert("[" thetag "]""[/" thetag "]"true))
        {
            eval(
thetag "_open = 1");
            
// Change the button status

            
pushstack(bbtagsthetag);
            
cstat();
        }
    }
    else
    {
        
// Find the last occurance of the opened tag
        
lastindex 0;

        for (
bbtags.lengthi++ )
        {
            if ( 
bbtags[i] == thetag )
            {
                
lastindex i;
            }
        }

        
// Close all tags opened up to that tag was opened
        
while (bbtags[lastindex])
        {
            
tagR...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/one_blog_with_main_page/bitrix/blog.post.edit/.default/template.php

Size: 23.09 kB Created: 2026-05-14 16:59:26 Modified: 2026-05-14 16:59:26 Dangers: 1
DescriptionMatch

Exploit execution Line: 369 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/script.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog/templates/one_blog_with_main_page/bitrix/blog.post.edit/.default/script.php

Size: 22.93 kB Created: 2018-02-28 10:31:20 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Function eval Line: 97 Warning

Potentially dangerous function `eval`

[https://www.php.net/eval]

eval(thetag "_open");

    if (
tagOpen == 0)
    {
        if (
doInsert("[" thetag "]""[/" thetag "]"true))
        {
            eval(
thetag "_open = 1");
            
// Change the button status

            
pushstack(bbtagsthetag);
            
cstat();
        }
    }
    else
    {
        
// Find the last occurance of the opened tag
        
lastindex 0;

        for (
bbtags.lengthi++ )
        {
            if ( 
bbtags[i] == thetag )
            {
                
lastindex i;
            }
        }

        
// Close all tags opened up to that tag was opened
        
while (bbtags[lastindex])
        {
            
tagR...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.sections.top/component.php

Size: 18.69 kB Created: 2026-05-14 16:58:41 Modified: 2026-05-14 16:58:41 Dangers: 1
DescriptionMatch

Sign 11413268 Line: 251 Dangerous

Malware Signature (hash: 11413268)

eval($_REQUEST

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.basket.basket/templates/.default/style.css

Size: 50.45 kB Created: 2023-01-31 12:51:01 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 683 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Label*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.basket.basket/templates/old_version_17/template.php

Size: 8.29 kB Created: 2018-02-28 10:31:52 Modified: 2026-05-12 15:55:50 Dangers: 4
DescriptionMatch

Exploit execution Line: 142 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/basket_items.php")

Exploit execution Line: 143 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/basket_items_delayed.php")

Exploit execution Line: 144 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/basket_items_subscribed.php")

Exploit execution Line: 145 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/basket_items_not_available.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.basket.basket/templates/bootstrap_v4/style.css

Size: 49.88 kB Created: 2023-01-31 12:52:02 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 683 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Label*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.basket.order.ajax/templates/.default/template.php

Size: 5.75 kB Created: 2026-05-15 23:21:13 Modified: 2026-05-15 23:21:13 Dangers: 7
DescriptionMatch

Exploit execution Line: 13 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/basket_confirm.php")

Exploit execution Line: 27 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/basket_items.php")

Exploit execution Line: 28 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/basket_items_delay.php")

Exploit execution Line: 29 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/basket_items_notavail.php")

Exploit execution Line: 30 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/basket_items_subscribe.php")

Exploit execution Line: 44 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/basket_person_type.php")

Exploit execution Line: 45 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/basket_props.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.basket.order.ajax/component.php

Size: 38.63 kB Created: 2026-05-15 23:21:13 Modified: 2026-05-15 23:21:13 Dangers: 1
DescriptionMatch

Sign 11413268 Line: 556 Dangerous

Malware Signature (hash: 11413268)

eVal($_POST

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.order.full/templates/.default/template.php

Size: 5.18 kB Created: 2026-05-15 23:21:13 Modified: 2026-05-15 23:21:13 Dangers: 7
DescriptionMatch

Exploit execution Line: 69 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/step1.php")

Exploit execution Line: 6 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/auth.php")

Exploit execution Line: 71 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/step2.php")

Exploit execution Line: 73 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/step3.php")

Exploit execution Line: 75 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/step4.php")

Exploit execution Line: 77 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/step5.php")

Exploit execution Line: 79 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/step6.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog.post.edit/templates/.default/template.php

Size: 21.54 kB Created: 2026-05-14 16:59:26 Modified: 2026-05-14 16:59:26 Dangers: 1
DescriptionMatch

Exploit execution Line: 242 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/neweditor.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog.post.edit/templates/micro/template.php

Size: 4.44 kB Created: 2023-01-31 12:39:35 Modified: 2026-05-12 15:55:49 Dangers: 1
DescriptionMatch

Exploit execution Line: 69 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/lhe.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/main.mail.form/templates/.default/style.css

Size: 15.59 kB Created: 2026-05-14 17:05:22 Modified: 2026-05-14 17:05:22 Dangers: 1
DescriptionMatch

Sign 7830f7a6 Line: 177 Dangerous

Malware Signature (hash: 7830f7a6)

NvcH

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/main.mail.form/templates/.default/template.php

Size: 19.36 kB Created: 2026-05-15 23:22:42 Modified: 2026-05-15 23:22:42 Dangers: 1
DescriptionMatch

Exploit nano Line: 235 Dangerous

Nano is a family of PHP webshells which are code golfed to be extremely stealthy and efficient

[https://github.com/s0md3v/nano]

$field['render']($field)

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/main.mail.form/templates/.default/style.min.css

Size: 12.97 kB Created: 2026-05-14 17:05:22 Modified: 2026-05-14 17:05:22 Dangers: 1
DescriptionMatch

Sign 7f5d33bf Line: 1 Dangerous

Malware Signature (hash: 7f5d33bf)

jb3B5

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/blog.post.comment.list/templates/.default/template.php

Size: 3.61 kB Created: 2018-06-26 15:08:10 Modified: 2026-05-12 15:55:49 Dangers: 1
DescriptionMatch

Exploit execution Line: 8 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/script.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.personal.subscribe.list/templates/.default/style.css

Size: 464.00 B Created: 2018-02-28 10:30:35 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Table*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/forum.topic.list/component.php

Size: 24.04 kB Created: 2026-05-14 16:58:26 Modified: 2026-05-14 16:58:26 Warns: 1
DescriptionMatch

Exploit double_var2 Line: 244 Warning

Double var technique is usually used for the obfuscation of malicious code

${$PAGEN_NAME}

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.notice.product/templates/.default/template.php

Size: 7.43 kB Created: 2018-03-14 13:12:31 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Function eval Line: 130 Warning

Potentially dangerous function `eval`

[https://www.php.net/eval]

eval( '('+res+')' );

                            if (
rs['ERRORS'].length 0)
                            {
                                if (
rs['ERRORS'] == 'NOTIFY_ERR_NULL')
                                    
BX('popup_n_error').innerHTML '<?=GetMessageJS('NOTIFY_ERR_NULL')?>';
                                else if (
rs['ERRORS'] == 'NOTIFY_ERR_CAPTHA')
                                    
BX('popup_n_error').innerHTML '<?=GetMessageJS('NOTIFY_ERR_CAPTHA')?>';
                                else if (
rs['ERRORS'] == 'NOTIFY_ERR_MAIL_EXIST')
                                {
                                    
BX('popup_n_error').innerHTML '<?=GetMessageJS('NOTIFY_ERR_MAIL_BUYERS_EXIST')?>';
                        ...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/app.layout/templates/.default/style.min.css

Size: 51.71 kB Created: 2026-05-15 23:22:49 Modified: 2026-05-15 23:22:49 Dangers: 2
DescriptionMatch

Sign 7830f7a6 Line: 494 Dangerous

Malware Signature (hash: 7830f7a6)

Nsb3Nl

Sign ee1cb326 Line: 494 Dangerous

Malware Signature (hash: ee1cb326)

9wZW

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/mobileapp.menu/templates/.default/template.php

Size: 12.55 kB Created: 2026-05-14 17:01:24 Modified: 2026-05-14 17:01:24 Warns: 1
DescriptionMatch

Function exec Warning

Potentially dangerous function `exec`

[https://www.php.net/exec]

exec("showAuthForm");
                }
            }
    <?endif;
?>

    if(BX.PULL)
    {
        BX.addCustomEvent("onPullExtendWatch", function(data) {
            BX.PULL.extendWatch(data.id);
        });

        BX.addCustomEvent("thisPageWillDie", function(data) {
            BX.PULL.clearWatch(data.page_id);
        });

        BX.addCustomEvent("onPullEvent", function (module_id, command, params)
        {
            if (module_id == 'main' && (command == 'user_authorize' || command == 'user_logout' || command == 'online_list'))
            {
                //app.onCustomEvent('onPullOnline', {...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.personal.order.list/templates/list/style.css

Size: 431.00 B Created: 2018-02-28 10:31:15 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Table*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.location.selector.system/templates/.default/template.php

Size: 18.01 kB Created: 2026-05-14 16:59:04 Modified: 2026-05-14 16:59:04 Warns: 1
DescriptionMatch

Function system Warning

Potentially dangerous function `system`

[https://www.php.net/system]

system(<?=CUtil::PhpToJSObject(array( 'scope' => 'slss-'.intval($arResult['RANDOM_TAG']), 'source' => $component->getPath().'/get.php''query' => array( 'BEHAVIOUR' => array( 'LANGUAGE_ID' => LANGUAGE_ID ), ), 'editUrl' => '?'.implode('&'$urlComponents), 'parentTagId' => intval($arResult['RANDOM_TAG']), 'useCodes' => $arResult['USE_CODES'], 'types' => $arResult['TYPES'], 'startSearchLen' => $component::START_SEARCH_LEN'pageSize' => $component::PAGE_SIZE'hugeTailLen' => $component::HUGE_TA...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/main.interface.form/templates/mobile/style.css

Size: 45.70 kB Created: 2023-01-31 12:50:43 Modified: 2026-05-12 15:55:50 Warns: 3 Dangers: 1
DescriptionMatch

Exploit infected_comment Line: 141 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Input*/

Exploit infected_comment Line: 342 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Money*/

Exploit infected_comment Line: 357 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Label*/

Sign 7f5d33bf Line: 69 Dangerous

Malware Signature (hash: 7f5d33bf)

Jhc2U2N

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/main.interface.form/templates/mobile/style.min.css

Size: 40.14 kB Created: 2023-01-31 12:50:43 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Sign 7f5d33bf Line: 1 Dangerous

Malware Signature (hash: 7f5d33bf)

Jhc2U2N

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.personal.cc.detail/templates/.default/style.css

Size: 455.00 B Created: 2018-02-28 10:31:38 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Table*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.crm.site.master/tools/pushchecker.php

Size: 2.27 kB Created: 2023-01-31 12:50:35 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Exploit execution Line: 120 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$modulePath)

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.crm.site.master/tools/modulechecker.php

Size: 5.15 kB Created: 2023-01-31 12:50:35 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Exploit execution Line: 142 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$modulePath)

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.bsm.site.master/tools/pushchecker.php

Size: 2.27 kB Created: 2023-01-31 12:50:35 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Exploit execution Line: 120 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$modulePath)

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.bsm.site.master/tools/modulechecker.php

Size: 3.12 kB Created: 2023-01-31 12:50:35 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Exploit execution Line: 125 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$modulePath)

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.catalog.controller/templates/.default/include/section_detail.php

Size: 340.00 B Created: 2026-05-15 23:22:52 Modified: 2026-05-15 23:22:52 Dangers: 1
DescriptionMatch

Exploit execution Line: 15 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER['DOCUMENT_ROOT'].'/bitrix/modules/iblock/admin/iblock_section_edit.php')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.catalog.controller/templates/.default/include/product_detail.php

Size: 340.00 B Created: 2026-05-15 23:22:52 Modified: 2026-05-15 23:22:52 Dangers: 1
DescriptionMatch

Exploit execution Line: 15 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER['DOCUMENT_ROOT'].'/bitrix/modules/iblock/admin/iblock_element_edit.php')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/main.ui.grid/templates/.default/src/css/style.css

Size: 80.81 kB Created: 2026-05-14 17:06:46 Modified: 2026-05-14 17:06:46 Dangers: 1
DescriptionMatch

Sign d97f004d Line: 2227 Dangerous

Malware Signature (hash: d97f004d)

zdGF0

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sale.personal.profile.list/templates/.default/style.css

Size: 1.64 kB Created: 2018-02-28 10:30:48 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Table*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/report.view/templates/admin/template.php

Size: 55.11 kB Created: 2026-05-14 17:00:48 Modified: 2026-05-14 17:00:48 Warns: 1
DescriptionMatch

Function eval Warning

Potentially dangerous function `eval`

[https://www.php.net/eval]

eval('response = ' data);
                if (
response)
                {
                    if (
response.imageData)
                    {
                        if (
response.imageData.substr(0,10) === 'data:image')
                        {
                            
img BX('report-chart-image');
                            
img.src response.imageData;
                            if (
response.legendInfo)
                            {
                                var 
legendContainer BX('report-chart-legend-container');
                                var 
legendRowExample BX('report-chart-legend-row-example');
                                var 
chartType requestData['type'];
                                var 
legendNewRowlegendSticklegend...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog/templates/.default/section.php

Size: 2.45 kB Created: 2023-03-30 10:38:41 Modified: 2026-05-12 15:55:49 Dangers: 2
DescriptionMatch

Exploit execution Line: 77 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"] . "/" $this->GetFolder()

Exploit execution Line: 81 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"]."/".$this->GetFolder()

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog/templates/bootstrap_v4/section.php

Size: 2.48 kB Created: 2023-03-30 10:38:41 Modified: 2026-05-12 15:55:49 Dangers: 1
DescriptionMatch

Exploit execution Line: 75 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"] . "/" $this->GetFolder()

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog/templates/store_v3/section.php

Size: 2.48 kB Created: 2023-03-30 10:38:41 Modified: 2026-05-12 15:55:49 Dangers: 1
DescriptionMatch

Exploit execution Line: 75 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"] . "/" $this->GetFolder()

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/photogallery.detail.list.ex/templates/.default/bitrix/blog.post.comment/photogallery/template.php

Size: 18.81 kB Created: 2023-01-31 12:39:40 Modified: 2026-05-12 15:55:50 Dangers: 2
DescriptionMatch

Exploit execution Line: 144 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/lhe.php")

Exploit execution Line: 30 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$templateFolder."/script.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/photogallery.detail.list.ex/templates/.default/template.php

Size: 13.03 kB Created: 2026-05-14 16:59:41 Modified: 2026-05-14 16:59:41 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 124 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*width*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.smart.filter/templates/.default_old/themes/red/colors.css

Size: 12.37 kB Created: 2018-02-28 10:31:25 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 5 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Track*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.smart.filter/templates/.default_old/themes/yellow/colors.css

Size: 11.75 kB Created: 2018-02-28 10:31:25 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 5 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Track*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.smart.filter/templates/.default_old/themes/green/colors.css

Size: 11.65 kB Created: 2018-02-28 10:31:25 Modified: 2026-05-12 15:55:49 Warns: 1 Dangers: 1
DescriptionMatch

Exploit infected_comment Line: 5 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Track*/

Sign ae7830db Line: 2 Dangerous

Malware Signature (hash: ae7830db)

Y2hy

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.smart.filter/templates/.default_old/style.css

Size: 34.31 kB Created: 2018-02-28 10:31:25 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 193 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Track*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.smart.filter/templates/visual_horizontal/themes/red/colors.css

Size: 12.37 kB Created: 2018-02-28 10:31:25 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 5 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Track*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.smart.filter/templates/visual_horizontal/themes/yellow/colors.css

Size: 11.75 kB Created: 2018-02-28 10:31:25 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 5 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Track*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.smart.filter/templates/visual_horizontal/themes/green/colors.css

Size: 11.65 kB Created: 2018-02-28 10:31:25 Modified: 2026-05-12 15:55:49 Warns: 1 Dangers: 1
DescriptionMatch

Exploit infected_comment Line: 5 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Track*/

Sign ae7830db Line: 2 Dangerous

Malware Signature (hash: ae7830db)

Y2hy

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.smart.filter/templates/visual_horizontal/style.css

Size: 33.95 kB Created: 2018-02-28 10:31:25 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 178 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Track*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.smart.filter/templates/visual_vertical/themes/red/colors.css

Size: 12.37 kB Created: 2018-02-28 10:31:24 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 5 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Track*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.smart.filter/templates/visual_vertical/themes/yellow/colors.css

Size: 11.75 kB Created: 2018-02-28 10:31:24 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 5 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Track*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.smart.filter/templates/visual_vertical/themes/green/colors.css

Size: 11.65 kB Created: 2018-02-28 10:31:24 Modified: 2026-05-12 15:55:49 Warns: 1 Dangers: 1
DescriptionMatch

Exploit infected_comment Line: 5 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Track*/

Sign ae7830db Line: 2 Dangerous

Malware Signature (hash: ae7830db)

Y2hy

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.smart.filter/templates/visual_vertical/style.css

Size: 33.95 kB Created: 2018-02-28 10:31:24 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 178 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Track*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.smart.filter/component.php

Size: 32.11 kB Created: 2026-05-15 23:21:24 Modified: 2026-05-15 23:21:24 Warns: 2
DescriptionMatch

Exploit double_var2 Line: 27 Warning

Double var technique is usually used for the obfuscation of malicious code

${$PREFILTER_NAME}

Exploit double_var2 Line: 659 Warning

Double var technique is usually used for the obfuscation of malicious code

${$FILTER_NAME}

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/main.file.input/templates/.default/style.css

Size: 4.80 kB Created: 2023-01-28 02:04:03 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Sign 7830f7a6 Line: 119 Dangerous

Malware Signature (hash: 7830f7a6)

NvcH

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/main.file.input/templates/.default/style.min.css

Size: 4.28 kB Created: 2023-01-28 02:04:03 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Sign 7830f7a6 Line: 1 Dangerous

Malware Signature (hash: 7830f7a6)

NvcH

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/main.file.input/templates/mobile/style.css

Size: 5.02 kB Created: 2023-01-28 02:05:47 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Sign 7830f7a6 Line: 128 Dangerous

Malware Signature (hash: 7830f7a6)

NvcH

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/main.file.input/templates/mobile/style.min.css

Size: 4.48 kB Created: 2023-01-28 02:05:47 Modified: 2026-05-12 15:55:50 Dangers: 1
DescriptionMatch

Sign 7830f7a6 Line: 1 Dangerous

Malware Signature (hash: 7830f7a6)

NvcH

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/landing.start/lang/en/component.php

Size: 5.85 kB Created: 2026-05-15 23:23:16 Modified: 2026-05-15 23:23:16 Dangers: 1
DescriptionMatch

Sign 301ca578 Line: 36 Dangerous

Malware Signature (hash: 301ca578)

Trojan

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/landing.start/lang/de/component.php

Size: 6.55 kB Created: 2026-05-15 23:23:16 Modified: 2026-05-15 23:23:16 Dangers: 1
DescriptionMatch

Sign 301ca578 Line: 36 Dangerous

Malware Signature (hash: 301ca578)

Trojan

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/main.map/component.php

Size: 5.81 kB Created: 2026-05-14 17:05:23 Modified: 2026-05-14 17:05:23 Warns: 1 Dangers: 1
DescriptionMatch

Exploit execution Line: 157 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$full_path.".section.php")

Function eval Warning

Potentially dangerous function `eval`

[https://www.php.net/eval]

eval("return ".$CONDITION.";"))) continue; } $search_child false$search_path ''$full_path ''; if ($aMenu[1] <> '') { if(preg_match("'^(([A-Za-z]+://)|mailto:|javascript:)'i"$aMenu[1])) { $full_path $aMenu[1]; } else { $full_path trim(Rel2Abs(mb_substr($PARENT_PATHmb_strlen($_SERVER["DOCUMENT_ROOT"])), $aMenu[1])); $slash_pos mb_strrpos($full_path"/"); if ($slash_pos !== false) { $page mb_substr($full_path$slash_pos 1); if(($pos mb_strpos($page'?')) !== false$pag...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/forum.topic.active/component.php

Size: 18.51 kB Created: 2026-05-14 16:58:26 Modified: 2026-05-14 16:58:26 Warns: 1
DescriptionMatch

Exploit double_var2 Line: 11 Warning

Double var technique is usually used for the obfuscation of malicious code

${$s}

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sender.yandex.toloka.edit/templates/.default/style.css

Size: 78.31 kB Created: 2023-03-30 10:38:26 Modified: 2026-05-12 15:55:50 Dangers: 3
DescriptionMatch

Sign 7830f7a6 Line: 1074 Dangerous

Malware Signature (hash: 7830f7a6)

NvcH

Sign 7f5d33bf Line: 1379 Dangerous

Malware Signature (hash: 7f5d33bf)

jb3B5

Sign ae7830db Line: 1379 Dangerous

Malware Signature (hash: ae7830db)

Y29we

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/sender.yandex.toloka.edit/templates/.default/style.min.css

Size: 73.48 kB Created: 2023-03-30 10:38:26 Modified: 2026-05-12 15:55:50 Dangers: 3
DescriptionMatch

Sign 7830f7a6 Line: 16 Dangerous

Malware Signature (hash: 7830f7a6)

NvcH

Sign 7f5d33bf Line: 16 Dangerous

Malware Signature (hash: 7f5d33bf)

jb3B5

Sign ae7830db Line: 16 Dangerous

Malware Signature (hash: ae7830db)

Y29we

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/main.ui.filter/templates/.default/src/css/style.css

Size: 68.81 kB Created: 2026-05-15 23:22:31 Modified: 2026-05-15 23:22:31 Dangers: 1
DescriptionMatch

Sign d97f004d Line: 1179 Dangerous

Malware Signature (hash: d97f004d)

zdGF0

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/catalog.link.list/component.php

Size: 1.13 kB Created: 2023-01-28 02:06:27 Modified: 2026-05-12 15:55:49 Warns: 1
DescriptionMatch

Exploit double_var2 Line: 19 Warning

Double var technique is usually used for the obfuscation of malicious code

${$FN}

/var/www/pavrusru/data/www/pavrus.ru/bitrix/components/bitrix/main.user.link/component.php

Size: 20.01 kB Created: 2026-05-14 17:04:55 Modified: 2026-05-14 17:04:55 Dangers: 1
DescriptionMatch

Exploit execution Line: 456 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"].$folderPath."/card.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/fileman/block_editor/dialog.css

Size: 28.11 kB Created: 2023-03-30 10:38:37 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 466 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*OTHER*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/ui/progressround/src/css/style.css

Size: 3.50 kB Created: 2026-05-14 17:02:47 Modified: 2026-05-14 17:02:47 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 4 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/ui/progressround/dist/progressround.bundle.css

Size: 3.50 kB Created: 2026-05-14 17:02:47 Modified: 2026-05-14 17:02:47 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 4 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/ui/forms/ui.forms.css

Size: 39.42 kB Created: 2026-05-14 17:06:04 Modified: 2026-05-14 17:06:04 Warns: 6
DescriptionMatch

Exploit infected_comment Line: 629 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*clock*/

Exploit infected_comment Line: 643 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*phone*/

Exploit infected_comment Line: 653 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*chain*/

Exploit infected_comment Line: 696 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*angle*/

Exploit infected_comment Line: 745 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*clear*/

Exploit infected_comment Line: 7 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/ui/forms/ui.forms.min.css

Size: 33.75 kB Created: 2026-05-14 17:06:04 Modified: 2026-05-14 17:06:04 Warns: 5
DescriptionMatch

Exploit infected_comment Line: 15 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*clock*/

Exploit infected_comment Line: 23 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*phone*/

Exploit infected_comment Line: 31 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*chain*/

Exploit infected_comment Line: 60 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*angle*/

Exploit infected_comment Line: 80 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*clear*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/ui/cnt/ui.cnt.css

Size: 5.10 kB Created: 2026-05-14 17:06:04 Modified: 2026-05-14 17:06:04 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 9 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/ui/progressbar/src/css/style.css

Size: 4.41 kB Created: 2026-05-14 17:03:04 Modified: 2026-05-14 17:03:04 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 6 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/ui/progressbar/dist/progressbar.bundle.css

Size: 4.41 kB Created: 2026-05-14 17:03:04 Modified: 2026-05-14 17:03:04 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 6 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/ui/tooltip/src/css/style.css

Size: 13.23 kB Created: 2026-05-14 17:06:04 Modified: 2026-05-14 17:06:04 Dangers: 2
DescriptionMatch

Sign 7830f7a6 Line: 284 Dangerous

Malware Signature (hash: 7830f7a6)

NvcH

Sign ae7830db Line: 284 Dangerous

Malware Signature (hash: ae7830db)

Y29we

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/ui/tooltip/dist/tooltip.bundle.css

Size: 16.10 kB Created: 2026-05-14 17:06:04 Modified: 2026-05-14 17:06:04 Dangers: 1
DescriptionMatch

Sign 7f5d33bf Line: 288 Dangerous

Malware Signature (hash: 7f5d33bf)

jb3B5

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/ui/tooltip/dist/tooltip.bundle.min.css

Size: 14.36 kB Created: 2026-05-14 17:06:04 Modified: 2026-05-14 17:06:04 Dangers: 1
DescriptionMatch

Sign 7830f7a6 Line: 1 Dangerous

Malware Signature (hash: 7830f7a6)

NvcH

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/ui/tooltip/tooltip.min.css

Size: 11.92 kB Created: 2023-03-30 10:38:34 Modified: 2026-05-12 15:55:52 Dangers: 2
DescriptionMatch

Sign 7830f7a6 Line: 4 Dangerous

Malware Signature (hash: 7830f7a6)

NvcH

Sign ae7830db Line: 4 Dangerous

Malware Signature (hash: ae7830db)

Y29we

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/ui/fontawesome4/css/font-awesome.min.css

Size: 111.52 kB Created: 2026-05-14 17:03:04 Modified: 2026-05-14 17:03:04 Dangers: 1
DescriptionMatch

Sign 91535293 Line: 5 Dangerous

Malware Signature (hash: 91535293)

ls-la

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/ui/fontawesome4/css/font-awesome.css

Size: 132.89 kB Created: 2026-05-14 17:03:04 Modified: 2026-05-14 17:03:04 Dangers: 1
DescriptionMatch

Sign 91535293 Line: 3758 Dangerous

Malware Signature (hash: 91535293)

ls-la

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/ui/counter/ui.counter.css

Size: 2.54 kB Created: 2023-01-28 02:08:10 Modified: 2026-05-12 15:55:51 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 6 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*color*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/main/core/css/core_tooltip.css

Size: 8.60 kB Created: 2018-02-28 10:30:08 Modified: 2026-05-12 15:55:51 Dangers: 2
DescriptionMatch

Sign 7830f7a6 Line: 205 Dangerous

Malware Signature (hash: 7830f7a6)

NvcH

Sign ae7830db Line: 205 Dangerous

Malware Signature (hash: ae7830db)

Y29we

/var/www/pavrusru/data/www/pavrus.ru/bitrix/js/main/core/css/core_tooltip.min.css

Size: 7.59 kB Created: 2018-02-28 10:30:08 Modified: 2026-05-12 15:55:51 Dangers: 2
DescriptionMatch

Sign 7830f7a6 Line: 1 Dangerous

Malware Signature (hash: 7830f7a6)

NvcH

Sign ae7830db Line: 1 Dangerous

Malware Signature (hash: ae7830db)

Y29we

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/perfmon.utf8/wizard.php

Size: 19.77 kB Created: 2026-05-14 17:00:34 Modified: 2026-05-14 17:00:34 Dangers: 1
DescriptionMatch

Sign b236d073 Line: 597 Dangerous

Malware Signature (hash: b236d073)

/*;*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/books/themes/blue_default/components/bitrix/menu/horizontal_multilevel/style.css

Size: 4.49 kB Created: 2018-02-28 10:32:29 Modified: 2026-05-12 15:55:59 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 19 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/books/themes/blue_default/template_styles.css

Size: 3.71 kB Created: 2018-02-28 10:32:29 Modified: 2026-05-12 15:55:59 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 35 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/books/themes/red/components/bitrix/menu/horizontal_multilevel/style.css

Size: 4.58 kB Created: 2018-02-28 10:32:29 Modified: 2026-05-12 15:55:59 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 19 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/books/themes/red/template_styles.css

Size: 10.04 kB Created: 2018-02-28 10:32:29 Modified: 2026-05-12 15:55:59 Warns: 3
DescriptionMatch

Exploit infected_comment Line: 286 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Forum*/

Exploit infected_comment Line: 35 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

Exploit infected_comment Line: 412 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Blogs*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/books/themes/green/components/bitrix/menu/horizontal_multilevel/style.css

Size: 4.58 kB Created: 2018-02-28 10:32:28 Modified: 2026-05-12 15:55:59 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 19 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/books/themes/green/template_styles.css

Size: 10.04 kB Created: 2018-02-28 10:32:28 Modified: 2026-05-12 15:55:59 Warns: 3
DescriptionMatch

Exploit infected_comment Line: 286 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Forum*/

Exploit infected_comment Line: 35 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

Exploit infected_comment Line: 413 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Blogs*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/books/components/bitrix/menu/horizontal_multilevel/style.css

Size: 4.49 kB Created: 2018-02-28 10:32:28 Modified: 2026-05-12 15:55:59 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 19 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/books/template_styles.css

Size: 3.71 kB Created: 2018-02-28 10:32:28 Modified: 2026-05-12 15:55:59 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 35 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/xml_catalog/themes/red/template_styles.css

Size: 11.39 kB Created: 2018-02-28 10:32:30 Modified: 2026-05-12 15:56:00 Warns: 3
DescriptionMatch

Exploit infected_comment Line: 35 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

Exploit infected_comment Line: 364 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Forum*/

Exploit infected_comment Line: 492 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Blogs*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/xml_catalog/themes/green/template_styles.css

Size: 11.38 kB Created: 2018-02-28 10:32:30 Modified: 2026-05-12 15:56:00 Warns: 3
DescriptionMatch

Exploit infected_comment Line: 35 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

Exploit infected_comment Line: 364 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Forum*/

Exploit infected_comment Line: 490 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Blogs*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/xml_catalog/themes/orange_default/template_styles.css

Size: 11.38 kB Created: 2018-02-28 10:32:30 Modified: 2026-05-12 15:56:00 Warns: 3
DescriptionMatch

Exploit infected_comment Line: 35 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

Exploit infected_comment Line: 364 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Forum*/

Exploit infected_comment Line: 490 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Blogs*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/xml_catalog/components/bitrix/menu/horizontal_multilevel_silver/style.css

Size: 4.85 kB Created: 2018-02-28 10:32:30 Modified: 2026-05-12 15:56:00 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 21 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/xml_catalog/template_styles.css

Size: 11.38 kB Created: 2018-02-28 10:32:30 Modified: 2026-05-12 15:56:00 Warns: 3
DescriptionMatch

Exploit infected_comment Line: 35 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

Exploit infected_comment Line: 364 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Forum*/

Exploit infected_comment Line: 489 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Blogs*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/web20/themes/blue_default/template_styles.css

Size: 11.21 kB Created: 2018-02-28 10:32:30 Modified: 2026-05-12 15:56:00 Warns: 3
DescriptionMatch

Exploit infected_comment Line: 35 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

Exploit infected_comment Line: 366 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Forum*/

Exploit infected_comment Line: 491 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Blogs*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/web20/themes/gray/template_styles.css

Size: 11.21 kB Created: 2018-02-28 10:32:29 Modified: 2026-05-12 15:56:00 Warns: 3
DescriptionMatch

Exploit infected_comment Line: 35 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

Exploit infected_comment Line: 366 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Forum*/

Exploit infected_comment Line: 491 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Blogs*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/web20/themes/red/template_styles.css

Size: 11.21 kB Created: 2018-02-28 10:32:29 Modified: 2026-05-12 15:56:00 Warns: 3
DescriptionMatch

Exploit infected_comment Line: 35 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

Exploit infected_comment Line: 366 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Forum*/

Exploit infected_comment Line: 492 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Blogs*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/web20/themes/green/template_styles.css

Size: 11.22 kB Created: 2018-02-28 10:32:29 Modified: 2026-05-12 15:56:00 Warns: 3
DescriptionMatch

Exploit infected_comment Line: 35 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

Exploit infected_comment Line: 366 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Forum*/

Exploit infected_comment Line: 495 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Blogs*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/templates/ru/web20/template_styles.css

Size: 11.21 kB Created: 2018-02-28 10:32:29 Modified: 2026-05-12 15:55:59 Warns: 3
DescriptionMatch

Exploit infected_comment Line: 35 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Links*/

Exploit infected_comment Line: 367 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Forum*/

Exploit infected_comment Line: 492 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Blogs*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/modules/examples/public/language/ru/examples/download/download_balance.php

Size: 3.00 kB Created: 2018-02-28 10:32:44 Modified: 2026-05-12 15:55:59 Dangers: 2
DescriptionMatch

Exploit execution Line: 47 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"]."/bitrix/modules/main/include/prolog_before.php")

Exploit execution Line: 95 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"]."/404.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/modules/examples/public/language/ru/examples/download/download_private/download_private.php

Size: 3.71 kB Created: 2018-02-28 10:32:44 Modified: 2026-05-12 15:55:59 Dangers: 1
DescriptionMatch

Exploit execution Line: 127 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"]."/404.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/modules/examples/public/language/ru/examples/download/download.php

Size: 2.09 kB Created: 2018-02-28 10:32:44 Modified: 2026-05-12 15:55:59 Dangers: 2
DescriptionMatch

Exploit execution Line: 36 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"]."/bitrix/modules/main/include/prolog_before.php")

Exploit execution Line: 69 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"]."/404.php")

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bitrix/demo/scripts/template.php

Size: 15.72 kB Created: 2018-02-28 10:32:30 Modified: 2026-05-12 15:55:59 Warns: 1
DescriptionMatch

Function eval Line: 462 Warning

Potentially dangerous function `eval`

[https://www.php.net/eval]

eval(response);
            }

            
CAjaxForm.prototype.ShowError = function(errorMessage)
            {
                var 
errorContainer document.getElementById("error_container");
                var 
errorText document.getElementById("error_text");
                if (!
errorContainer || !errorText)
                    return;

                var 
waitWindow document.getElementById("wait");
                if (
waitWindow)
                    
waitWindow.style.display "none";

                
errorContainer.style.display 'block';
                
errorText.innerHTML strip_tags(errorMessage);

                var 
retryButton = ...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/intec/universesite/site/templates/universesite/components/bitrix/catalog.store/template.1/style.css

Size: 912.00 B Created: 2025-01-31 14:08:40 Modified: 2026-05-12 15:56:00 Warns: 1
DescriptionMatch

Exploit infected_comment Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Table*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/intec/universesite/site/templates/universesite/components/bitrix/support.ticket.edit/template.1/parts/script.php

Size: 10.92 kB Created: 2025-01-31 14:08:41 Modified: 2026-05-12 15:56:00 Warns: 1
DescriptionMatch

Function eval Line: 75 Warning

Potentially dangerous function `eval`

[https://www.php.net/eval]

eval(thetag "_open");

            if (
tagOpen == 0) {
                if (
DoInsert(objTextarea"<"+thetag+">""</"+thetag+">")) {
                    eval(
thetag "_open = 1");
                    eval(
"document.forms['support_edit'].elements['"+thetag+"'].value += '*'");
                }
            } else {
                
DoInsert(objTextarea"</"+thetag+">""");
                var 
buttonText = eval("document.forms['support_edit'].elements['"+thetag+"'].value");
          ...

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/intec/universesite/site/templates/universesite/components/bitrix/map.yandex.system/.default/template.php

Size: 7.16 kB Created: 2025-01-31 14:08:40 Modified: 2026-05-12 15:56:00 Warns: 1
DescriptionMatch

Function system Line: 206 Warning

Potentially dangerous function `system`

[https://www.php.net/system]

system (.default)',
            '
nodes': <?= JavaScript::toObject('#'.$sTemplateId) ?>,
            'loader': {
                'name': 'lazy'
            }
        });
    </script>
<?= Html::endTag('div')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/intec/universesite/site/templates/universesite/components/bitrix/map.google.system/.default/template.php

Size: 6.79 kB Created: 2025-01-31 14:08:41 Modified: 2026-05-12 15:56:00 Warns: 1
DescriptionMatch

Function system Line: 187 Warning

Potentially dangerous function `system`

[https://www.php.net/system]

system (.default)',
            '
nodes': <?= JavaScript::toObject('#'.$sTemplateId) ?>,
            'loader': {
                'name': 'lazy'
            }
        });
    </script>
<?= Html::endTag('div')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/intec/universesite/site/templates/universesite/components/intec.universe/system/basket.manager/template.php

Size: 4.98 kB Created: 2025-01-31 14:08:41 Modified: 2026-05-12 15:56:00 Warns: 1
DescriptionMatch

Function system Line: 137 Warning

Potentially dangerous function `system`

[https://www.php.net/system]

system (basket.manager)',
        '
loader': {
            '
options': {
                '
await': [
                    '
composite'
                ]
            }
        }
    })

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/intec/universesite/site/templates/universesite/components/intec.universe/main.stories/template.1/style.css

Size: 16.89 kB Created: 2025-01-31 14:08:41 Modified: 2026-05-12 15:56:00 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 2 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*popup*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bizsolutions/alpha/site/templates/bizsolutions.alpha/footer.php

Size: 9.02 kB Created: 2018-02-28 10:32:09 Modified: 2026-05-12 15:56:00 Dangers: 1
DescriptionMatch

Exploit execution Line: 146 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER['DOCUMENT_ROOT'] . SITE_DIR 'include/footer.socials.php')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bizsolutions/alpha/site/templates/bizsolutions.alpha/header.php

Size: 12.74 kB Created: 2018-02-28 10:32:09 Modified: 2026-05-12 15:56:00 Dangers: 1
DescriptionMatch

Exploit execution Line: 171 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER['DOCUMENT_ROOT'] . SITE_DIR 'include/header.socials.php')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bizsolutions/alpha/site/templates/bizsolutions.alpha/plugins/owl-carousel/owl.carousel.css

Size: 5.78 kB Created: 2018-02-28 10:32:02 Modified: 2026-05-12 15:56:00 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 130 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*empty*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bizsolutions/alpha/site/templates/bizsolutions.alpha/components/bitrix/catalog.section/catalog.items/template.php

Size: 1.25 kB Created: 2018-02-28 10:32:09 Modified: 2026-05-12 15:56:00 Dangers: 1
DescriptionMatch

Exploit execution Line: 16 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER['DOCUMENT_ROOT'] . $templateFolder '/top_panel.php')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bizsolutions/alpha/site/templates/bizsolutions.alpha/components/bitrix/main.profile/personal.page/style.css

Size: 14.67 kB Created: 2018-02-28 10:32:08 Modified: 2026-05-12 15:56:00 Warns: 2
DescriptionMatch

Exploit infected_comment Line: 191 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Table*/

Exploit infected_comment Line: 330 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Media*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bizsolutions/alpha/site/templates/bizsolutions.alpha/css/app.css

Size: 69.80 kB Created: 2018-02-28 10:32:09 Modified: 2026-05-12 15:56:00 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 927 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Pager*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bizsolutions/alpha/site/templates/bizsolutions.alpha/css/headers/header-v1.css

Size: 20.00 kB Created: 2018-02-28 10:32:09 Modified: 2026-05-12 15:56:00 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 896 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Brand*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/wizards/bizsolutions/alpha/site/public/ru/_index.php

Size: 11.61 kB Created: 2018-02-28 10:32:10 Modified: 2026-05-12 15:56:00 Dangers: 1
DescriptionMatch

Exploit execution Line: 162 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER['DOCUMENT_ROOT'] . SITE_DIR 'include/index.news.php')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/panel/sale/preset.css

Size: 12.25 kB Created: 2023-01-31 12:51:01 Modified: 2026-05-12 15:55:57 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 21 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*title*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/panel/main/adminstyles_fixed.css

Size: 20.95 kB Created: 2023-01-28 02:03:49 Modified: 2026-05-12 15:55:57 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 240 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*Lamps*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/css/yandex.metrika/admin.css

Size: 19.63 kB Created: 2024-08-07 13:23:30 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 40 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*reset*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/css/main/table/style.css

Size: 5.43 kB Created: 2023-01-31 12:50:43 Modified: 2026-05-12 15:55:50 Dangers: 2
DescriptionMatch

Sign 7830f7a6 Line: 155 Dangerous

Malware Signature (hash: 7830f7a6)

NvcH

Sign 7f5d33bf Line: 155 Dangerous

Malware Signature (hash: 7f5d33bf)

jb3B5

/var/www/pavrusru/data/www/pavrus.ru/bitrix/css/main/table/style.min.css

Size: 4.96 kB Created: 2023-01-31 12:50:43 Modified: 2026-05-12 15:55:50 Dangers: 2
DescriptionMatch

Sign 7830f7a6 Line: 1 Dangerous

Malware Signature (hash: 7830f7a6)

NvcH

Sign 7f5d33bf Line: 1 Dangerous

Malware Signature (hash: 7f5d33bf)

jb3B5

/var/www/pavrusru/data/www/pavrus.ru/bitrix/css/main/system.auth/flat/style.css

Size: 5.62 kB Created: 2023-01-28 02:03:16 Modified: 2026-05-12 15:55:50 Warns: 1
DescriptionMatch

Exploit infected_comment Line: 6 Warning

Comments composed by 5 random chars usually used to detect if a file is infected yet

/*block*/

/var/www/pavrusru/data/www/pavrus.ru/bitrix/tools/vote/vote_chart.php

Size: 469.00 B Created: 2023-01-31 12:39:15 Modified: 2026-05-12 15:55:59 Dangers: 1
DescriptionMatch

Exploit execution Line: 10 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER["DOCUMENT_ROOT"]."/".$file)

/var/www/pavrusru/data/www/pavrus.ru/bitrix/tools/catalog/section_save.php

Size: 291.00 B Created: 2023-01-31 12:49:08 Modified: 2026-05-12 15:55:59 Dangers: 1
DescriptionMatch

Exploit execution Line: 9 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER['DOCUMENT_ROOT'].'/bitrix/modules/iblock/admin/iblock_section_edit.php')

/var/www/pavrusru/data/www/pavrus.ru/bitrix/tools/catalog/product_save.php

Size: 291.00 B Created: 2023-01-31 12:49:08 Modified: 2026-05-12 15:55:59 Dangers: 1
DescriptionMatch

Exploit execution Line: 9 Dangerous

RCE (Remote Code Execution) allow remote attackers to execute PHP code on the target machine via HTTP

[https://cwe.mitre.org/data/definitions/77.html, https://cwe.mitre.org/data/definitions/78.html]

include($_SERVER['DOCUMENT_ROOT'].'/bitrix/modules/iblock/admin/iblock_element_edit.php')

/var/www/pavrusru/data/www/pavrus.ru/antibot/index.php

Size: 4.06 kB Created: 2025-02-13 16:28:47 Modified: 2026-05-12 15:55:48 Warns: 1
DescriptionMatch

Function exec Warning

Potentially dangerous function `exec`

[https://www.php.net/exec]

exec('whoami') == get_current_user()) { $result .= '<li style="color:green;">file owner = php user (good practice)</li>'; } elseif (get_current_user() == 'root') { $result .= '<li style="color:red;">Uploading files by the root user is a bad practice!</li>'; } else { $result .= '<li style="color:red;">file owner != php user (bad practice)</li>'; } } if (extension_loaded('curl')) { $result .= '<li style="color:green;">CURL - installed</li>'; } else { $result .= '<li style="color:red;">CURL - not i...

/var/www/pavrusru/data/www/pavrus.ru/antibot/.htaccess

Size: 339.00 B Created: 2023-03-20 15:56:54 Modified: 2026-05-12 15:55:48 Dangers: 1
DescriptionMatch

Exploit file_prepend Line: 7 Dangerous

LFI (Local File Inclusion), prepending a file at the bottom of every others PHP files, allow remote attackers to inject and execute arbitrary commands or code on the target machine

php_value auto_prepend_file