PT-2006-3110 · Unknown · Advanced Poll
Aliaksandr Hartsuyeu
+1
·
Published
2006-05-01
·
Updated
2017-07-20
·
CVE-2006-2131
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Advanced Poll version 2.0.4
Description
The issue allows remote attackers to spoof the source IP and bypass voting restrictions. This is because the
include/class poll.php file in Advanced Poll uses the HTTP X FORWARDED FOR (X-Forwarded-For HTTP header) to identify the IP address of a client.Recommendations
For Advanced Poll version 2.0.4, consider modifying the
include/class poll.php file to use a more reliable method for identifying client IP addresses, such as checking the REMOTE ADDR variable, as a temporary workaround until a patch is available. Restrict access to voting functionality to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Advanced Poll