漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Improper Restriction of Excessive Authentication Attempts in phpipam/phpipam
Vulnerability Description
phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X-Forwarded-For' header. The issue lies in the 'get_user_ip()' function in 'class.Common.php' at lines 1044 and 1045, where the presence of the 'X-Forwarded-For' header is checked and used instead of 'REMOTE_ADDR'. This vulnerability allows attackers to perform brute force attacks on user accounts, including the admin account. The issue is fixed in version 1.7.0.
CVSS Information
N/A
Vulnerability Type
过多认证尝试的限制不恰当
Vulnerability Title
phpIPAM 安全漏洞
Vulnerability Description
phpIPAM是phpIPAM开源的一套开源的基于PHP和MySQL的IP地址管理应用程序(IPAM)。 phpIPAM 1.5.1版本存在安全漏洞。攻击者利用该漏洞通过“X-Forwarded-For”标头绕过 IP 阻止机制,暴力破解用户密码。
CVSS Information
N/A
Vulnerability Type
N/A