CVE-2006-6679

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/12/2006
Last modified:
25/01/2024

Description

Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL, which allows remote attackers to gain unauthorized access by spoofing this header.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:chetcpasswd_project:chetcpasswd:*:*:*:*:*:*:*:* 2.4 (excluding)