CVE Database
/

CVE-2011-0398

Back to search

CVE-2011-0398

Published: Jan 10, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

The Piwik_Common::getIP function in Piwik before 1.1 does not properly determine the client IP address, which allows remote attackers to bypass intended geolocation and logging functionality via (1) use of a private (aka RFC 1918) address behind a proxy server or (2) spoofing of the X-Forwarded-For HTTP header.

VendorProductVersions

n/a

n/a

affected
n/a

References

45787
vdb-entry
x_refsource_BID
70384
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now