First published: Wed May 31 2006(Updated: )
vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | =2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2702 has a medium severity rating due to its potential to allow remote attackers to spoof their IP address.
To fix CVE-2006-2702, it is recommended to upgrade WordPress to a version later than 2.0.2.
CVE-2006-2702 affects installations of WordPress version 2.0.2, particularly those running on Mac OS X.
The exploit method for CVE-2006-2702 involves sending a crafted PC_REMOTE_ADDR HTTP header to spoof the REMOTE_ADDR variable.
CVE-2006-2702 is generally considered outdated but could be a risk for legacy systems still running the vulnerable version of WordPress.