PunBB/BLOG:CMS Origin Spoofing Vulnerability

PunBB and Blog:CMS allow attackers to hide addresses using the X_FORWARDED_FOR field in the HTTP header.

These applications accept the values supplied by users in HTTP headers as the originating IP address of a request. It is possible for a remote host to supply a fake IP address in the environment variable that would obscure the origin on the request.


 

Privacy Statement
Copyright 2010, SecurityFocus