CVE
- Id
- 23117
- CVE No.
- CVE-2006-7013
- Status
- Candidate
- Description
- ** DISPUTED ** QueryString.php in Simple Machines Forum (SMF) 1.0.7 and earlier, and 1.1rc2 and earlier, allows remote attackers to more easily spoof the IP address and evade banning via a modified X-Forwarded-For HTTP header, which is preferred instead of other more reliable sources for the IP address. NOTE: the original researcher claims that the vendor has disputed this issue.
- Phase
- Assigned (20070214)
- Votes
- None (candidate not yet proposed)
- Comments