7.5

CVE-2006-6679

Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL, which allows remote attackers to gain unauthorized access by spoofing this header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Chetcpasswd ProjectChetcpasswd Version < 2.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.07% 0.789
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

http://sourceforge.net/project/shownotes.php?group_id=68912&release_id=466649
Product
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=394454
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=116371297325564&w=2
Third Party Advisory
Mailing List
http://secunia.com/advisories/22967
Third Party Advisory
Broken Link
Permissions Required
http://www.osvdb.org/30544
Broken Link
http://www.securityfocus.com/bid/21102
Third Party Advisory
Broken Link
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/30451
Third Party Advisory
VDB Entry