First published: Thu Feb 15 2007(Updated: )
** DISPUTED ** QueryString.php in Simple Machines Forum (SMF) 1.0.7 and earlier, and 1.1rc2 and earlier, allows remote attackers to more easily spoof the IP address and evade banning via a modified X-Forwarded-For HTTP header, which is preferred instead of other more reliable sources for the IP address. NOTE: the original researcher claims that the vendor has disputed this issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple Machines Forum | <=1.0.7 | |
Simple Machines Forum | <=1.1_rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-7013 is considered a medium severity vulnerability due to its potential for IP address spoofing.
To fix CVE-2006-7013, upgrade Simple Machines Forum to version 1.0.8 or later, or 1.1.x or later.
CVE-2006-7013 affects all versions of Simple Machines Forum up to and including 1.0.7 and 1.1rc2.
CVE-2006-7013 allows remote attackers to spoof IP addresses and bypass banning mechanisms.
CVE-2006-7013 is not a concern for current versions as subsequent releases have patched the vulnerability.