CVE-2001-0908 Information

Description

CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers which allows clients to spoof their public IP address e.g. through Network Address Translation (NAT).

Reference

http://marc.info/?l=bugtraq&m=100638693315933&w=2 http://www.securityfocus.com/bid/3566 https://exchange.xforce.ibmcloud.com/vulnerabilities/7538

Share on: