CVE-2006-2702: Medium severity WordPress vulnerability
vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PCREMOTEADDR HTTP header, which vars.php uses to redefine $SERVER['REMOTEADDR'].
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2702?
CVE-2006-2702 has a medium severity rating due to its potential to allow remote attackers to spoof their IP address.
How do I fix CVE-2006-2702?
To fix CVE-2006-2702, it is recommended to upgrade WordPress to a version later than 2.0.2.
Who is affected by CVE-2006-2702?
CVE-2006-2702 affects installations of WordPress version 2.0.2, particularly those running on Mac OS X.
What is the exploit method for CVE-2006-2702?
The exploit method for CVE-2006-2702 involves sending a crafted PC_REMOTE_ADDR HTTP header to spoof the REMOTE_ADDR variable.
Is CVE-2006-2702 still a concern today?
CVE-2006-2702 is generally considered outdated but could be a risk for legacy systems still running the vulnerable version of WordPress.