Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Gallery 2 up to 2.0.2 allows remote attackers to spoof their IP address via a modified X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is checked by Gallery before other more reliable sources of IP address information, such as REMOTE_ADDR.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Gallery X-Forwarded-For HTTP头进行IP地址欺骗漏洞
Vulnerability Description
Gallery 2至2.0.2可以让远程攻击者通过一个修改的X-Forwarded-For (X_FORWARDED_FOR) HTTP头进行IP地址欺骗,Gallery在其它更可靠的IP地址信息来源(如REMOTE_ADDR)之前要对该地址进行检查。
CVSS Information
N/A
Vulnerability Type
N/A