PT-2006-7280 · Pedro Lineu Orso · Chetcpasswd
Riclem
·
Published
2006-12-21
·
Updated
2024-01-25
·
CVE-2006-6679
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Pedro Lineu Orso chetcpasswd versions prior to 2.4
Description:
The issue allows remote attackers to gain unauthorized access by spoofing the
X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL. This is due to the software relying on this header for verification.Recommendations:
For versions prior to 2.4, consider disabling the use of the
X-Forwarded-For header in ACL verification until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation.Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chetcpasswd