PT-2006-7280 · Pedro Lineu Orso · Chetcpasswd
Riclem
·
Publicado
2006-12-21
·
Atualizado
2024-01-25
·
CVE-2006-6679
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Pedro Lineu Orso chetcpasswd versions prior to 2.4
Description:
The issue allows remote attackers to gain unauthorized access by spoofing the
X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL. This is due to the software relying on this header for verification.Recommendations:
For versions prior to 2.4, consider disabling the use of the
X-Forwarded-For header in ACL verification until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation.Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Chetcpasswd