Invision Power Board Potential IP Address Spoofing Vulnerability

It is reported that Invision Power Board is prone to an IP address spoofing vulnerability. If an attacker is using a proxy to access a remote forum, the application logs the attacker's internal IP address on the LAN, instead of the real IP address of the proxy.

This issue is reported to affect Invision Power Board version 1.3, however, it is likely that other versions are affected as well.


 

Privacy Statement
Copyright 2010, SecurityFocus