Vulnerabilities > CVE-2004-1950 - Unspecified vulnerability in PHPbb Group PHPbb
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.
Vulnerable Configurations
References
- http://marc.info/?l=bugtraq&m=108239864203144&w=2
- http://marc.info/?l=bugtraq&m=108239864203144&w=2
- http://marc.info/?l=bugtraq&m=108241122908409&w=2
- http://marc.info/?l=bugtraq&m=108241122908409&w=2
- http://secunia.com/advisories/11434
- http://secunia.com/advisories/11434
- http://www.securityfocus.com/bid/10170
- http://www.securityfocus.com/bid/10170
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15909
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15909