漏洞信息详情
Pedro Lineu Orso chetcpasswd X-Forwarded-For HTTP报头欺骗未授权访问漏洞
漏洞简介
Pedro Lineu Orso chetcpasswd的2.4之前版本依赖X-Forwarded-For HTTP报头来验证客户端在IP地址ACL上的状态,远程攻击者可以通过欺骗报头来获取未授权访问。
漏洞公告
参考网址
来源:MISC
链接:http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=394454
来源:CONFIRM
链接:http://sourceforge.net/project/shownotes.php?group_id=68912&release_id=466649
来源:BID
链接:https://www.securityfocus.com/bid/21102
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/30451
来源:BUGTRAQ
链接:http://marc.info/?l=bugtraq&m=116371297325564&w=2
来源:OSVDB
链接:http://www.osvdb.org/30544
来源:SECUNIA
链接:http://secunia.com/advisories/22967
受影响实体
- Pedro_lineu_orso Chetcpasswd:1.12<!--2000-1-1-->
- Pedro_lineu_orso Chetcpasswd:2.1<!--2000-1-1-->
- Pedro_lineu_orso Chetcpasswd:2.2.1<!--2000-1-1-->
- Pedro_lineu_orso Chetcpasswd:2.3.1<!--2000-1-1-->
- Pedro_lineu_orso Chetcpasswd:2.3.3<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...