CVE-2004-1950: Medium severity phpbb group phpbb vulnerability
Published Apr 19, 2004
·Updated
phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.
Affected Software
13 affected components
Phpbb Group Phpbb=2.0.5
Phpbb Group Phpbb=2.0.7a
Phpbb Group Phpbb=2.0.8
Phpbb Group Phpbb=2.0.1
Phpbb Group Phpbb=2.0.3
Phpbb Group Phpbb=2.0.4
Phpbb Group Phpbb=2.0.7
Phpbb Group Phpbb=2.0.8a
Phpbb Group Phpbb=2.0.6d
Phpbb Group Phpbb=2.0.2
Phpbb Group Phpbb=2.0.6c
Phpbb Group Phpbb=2.0.6
Phpbb Group Phpbb=2.0.0
Remediation
Patch Available
Patch Available
Event History
Apr 19, 2004
CVE Published
04:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1950?
CVE-2004-1950 has a moderate severity rating due to the potential for IP address spoofing.
2
How do I fix CVE-2004-1950?
To mitigate CVE-2004-1950, upgrade to phpBB version 2.0.9 or later, which no longer trusts the X-Forwarded-For header.
3
Who is affected by CVE-2004-1950?
CVE-2004-1950 affects phpBB versions 2.0.8 and earlier.
4
What type of vulnerability is CVE-2004-1950?
CVE-2004-1950 is an IP spoofing vulnerability.
5
Can CVE-2004-1950 be exploited remotely?
Yes, CVE-2004-1950 can be exploited remotely by attackers to spoof their IP addresses.