PHPBB Common.php IP欺骗地址漏洞

漏洞信息详情

PHPBB Common.php IP欺骗地址漏洞

漏洞简介

phpBB 2.0.8a和早期版本信任HTTP头中X-Forwarded-For的IP地址,远程攻击者可以借助该漏洞欺骗IP地址。

漏洞公告

The vendor has released version 2.0.9 of phpBB that addresses this issue.
phpBB Group phpBB 2.0 .0

phpBB Group phpBB 2.0.1

phpBB Group phpBB 2.0.2

phpBB Group phpBB 2.0.3

phpBB Group phpBB 2.0.4

phpBB Group phpBB 2.0.5

phpBB Group phpBB 2.0.6 c

phpBB Group phpBB 2.0.6 d

phpBB Group phpBB 2.0.6

phpBB Group phpBB 2.0.7

phpBB Group phpBB 2.0.7 a

phpBB Group phpBB 2.0.8 a

phpBB Group phpBB 2.0.8

参考网址

来源: XF
名称: phbb-common-ip-spoofing(15909)
链接:http://xforce.iss.net/xforce/xfdb/15909

来源: BID
名称: 10170
链接:http://www.securityfocus.com/bid/10170

来源: SECUNIA
名称: 11434
链接:http://secunia.com/advisories/11434

来源: BUGTRAQ
名称: 20040419 Re: phpBB 2.0.8a and lower – IP spoofing vulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108241122908409&w=2

来源: BUGTRAQ
名称: 20040419 phpBB 2.0.8a and lower – IP spoofing vulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108239864203144&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享