漏洞信息详情
PHPBB Common.php IP欺骗地址漏洞
- CNNVD编号:CNNVD-200404-068
- 危害等级: 中危
- CVE编号:
CVE-2004-1950
- 漏洞类型:
设计错误
- 发布时间:
2004-04-19
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
phpbb_group - 漏洞来源:
Discovery is credi… -
漏洞简介
phpBB 2.0.8a和早期版本信任HTTP头中X-Forwarded-For的IP地址,远程攻击者可以借助该漏洞欺骗IP地址。
漏洞公告
The vendor has released version 2.0.9 of phpBB that addresses this issue.
phpBB Group phpBB 2.0 .0
-
phpBB Group phpBB-2.0.9.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.9.zip?download
phpBB Group phpBB 2.0.1
-
phpBB Group phpBB-2.0.9.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.9.zip?download
phpBB Group phpBB 2.0.2
-
phpBB Group phpBB-2.0.9.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.9.zip?download
phpBB Group phpBB 2.0.3
-
phpBB Group phpBB-2.0.9.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.9.zip?download
phpBB Group phpBB 2.0.4
-
phpBB Group phpBB-2.0.9.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.9.zip?download
phpBB Group phpBB 2.0.5
-
phpBB Group phpBB-2.0.9.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.9.zip?download
phpBB Group phpBB 2.0.6 c
-
phpBB Group phpBB-2.0.9.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.9.zip?download
phpBB Group phpBB 2.0.6 d
-
phpBB Group phpBB-2.0.9.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.9.zip?download
phpBB Group phpBB 2.0.6
-
phpBB Group phpBB-2.0.9.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.9.zip?download
phpBB Group phpBB 2.0.7
-
phpBB Group phpBB-2.0.9.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.9.zip?download
phpBB Group phpBB 2.0.7 a
-
phpBB Group phpBB-2.0.9.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.9.zip?download
phpBB Group phpBB 2.0.8 a
-
phpBB Group phpBB-2.0.9.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.9.zip?download
phpBB Group phpBB 2.0.8
-
phpBB Group phpBB-2.0.9.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.9.zip?download
参考网址
来源: XF
名称: phbb-common-ip-spoofing(15909)
链接:http://xforce.iss.net/xforce/xfdb/15909
来源: BID
名称: 10170
链接:http://www.securityfocus.com/bid/10170
来源: SECUNIA
名称: 11434
链接:http://secunia.com/advisories/11434
来源: BUGTRAQ
名称: 20040419 Re: phpBB 2.0.8a and lower – IP spoofing vulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108241122908409&w=2
来源: BUGTRAQ
名称: 20040419 phpBB 2.0.8a and lower – IP spoofing vulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108239864203144&w=2