5

CVE-2006-2131

include/class_poll.php in Advanced Poll 2.0.4 uses the HTTP_X_FORWARDED_FOR (X-Forwarded-For HTTP header) to identify the IP address of a client, which makes it easier for remote attackers to spoof the source IP and bypass voting restrictions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Advanced PollAdvanced Poll Version2.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.62% 0.729
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://evuln.com/vulns/131/summary.html
http://secunia.com/advisories/19899
http://www.vupen.com/english/advisories/2006/1603
https://exchange.xforce.ibmcloud.com/vulnerabilities/26154