5

CVE-2005-4687

PunBB 1.2.9, used alone or with F-ART BLOG:CMS, may trust a client's IP address as specified in the X-Forwarded-For HTTP header rather than the TCP/IP stack, which allows remote attackers to misrepresent their IP address by sending a modified header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F-art AgencyBlog Cms Version3.0
F-art AgencyBlog Cms Version3.1
F-art AgencyBlog Cms Version3.1.2
F-art AgencyBlog Cms Version3.1.3
F-art AgencyBlog Cms Version3.1.4
F-art AgencyBlog Cms Version3.6.2
F-art AgencyBlog Cms Version3.6.4
F-art AgencyBlog Cms Version4.0.0
F-art AgencyBlog Cms Version4.0.0a
F-art AgencyBlog Cms Version4.0.0b
F-art AgencyBlog Cms Version4.0.0c
F-art AgencyBlog Cms Version4.0.0d
PunbbPunbb Version1.2.1
PunbbPunbb Version1.2.2
PunbbPunbb Version1.2.3
PunbbPunbb Version1.2.4
PunbbPunbb Version1.2.5
PunbbPunbb Version1.2.6
PunbbPunbb Version1.2.7
PunbbPunbb Version1.2.8
PunbbPunbb Version1.2.9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.39% 0.688
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/17425
Patch
Vendor Advisory
http://secunia.com/advisories/17433
Patch
Vendor Advisory
http://www.punbb.org/changelogs/1.2.9_to_1.2.10.txt
http://www.securityfocus.com/bid/15326
Patch