CWE Database
/

CWE-348

Back to CWE list

CWE-348

Use of Less Trusted Source

Base
Draft

Description

The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.

Common Consequences

Scope

Access Control

Impact

Bypass Protection Mechanism, Gain Privileges or Assume Identity

CVE-2001-0860

Product uses IP address provided by a client, instead of obtaining it from the packet headers, allowing easier spoofing.

CVE-2004-1950

Web product uses the IP address in the X-Forwarded-For HTTP header instead of a server variable that uses the connecting IP address, allowing filter bypass.

CVE-2001-0908

Product logs IP address specified by the client instead of obtaining it from the packet headers, allowing information hiding.

CVE-2006-1126

PHP application uses IP address from X-Forwarded-For HTTP header, instead of REMOTE_ADDR.

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now