Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PunBB/BLOG:CMS Origin Spoofing Vulnerability

PunBB and Blog:CMS allow attackers to hide addresses using the X_FORWARDED_FOR field in the HTTP header.

These applications accept the values supplied by users in HTTP headers as the originating IP address of a request. It is possible for a remote host to supply a fake IP address in the environment variable that would obscure the origin on the request.







 

Privacy Statement
Copyright 2009, SecurityFocus