PT-2007-1292 · Simple Machines · Simple Machines Forum
Jessica Hope
·
Published
2007-02-15
·
Updated
2024-08-07
·
CVE-2006-7013
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Simple Machines Forum (SMF) versions 1.0.7 and earlier
Simple Machines Forum (SMF) version 1.1rc2 and earlier
Description
The issue allows remote attackers to more easily spoof the IP address and evade banning via a modified
X-Forwarded-For HTTP header. This header is preferred over other more reliable sources for the IP address.Recommendations
For Simple Machines Forum (SMF) versions 1.0.7 and earlier, consider updating to a newer version to mitigate the risk, although the exact fix version is not specified.
For Simple Machines Forum (SMF) version 1.1rc2 and earlier, consider updating to a newer version to mitigate the risk, although the exact fix version is not specified.
As a temporary workaround, consider restricting the use of the
X-Forwarded-For HTTP header to minimize the risk of IP address spoofing.
At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simple Machines Forum