|
PunBB/BLOG:CMS Origin Spoofing Vulnerability
PunBB and Blog:CMS allow attackers to hide addresses using the X_FORWARDED_FOR field in the HTTP header. These applications accept the values supplied by users in HTTP headers as the originating IP address of a request. It is possible for a remote host to supply a fake IP address in the environment variable that would obscure the origin on the request. |
|
Privacy Statement |