CVE-2006-2702
published 2006-05-31CVE-2006-2702: vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
2.92%
85.5th percentile
vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 2.0.3-1 (bookworm) | wordpress 2.0.3-1 (bookworm) |
| wordpress | wordpress | — | — |
| wordpress | wordpress | >= 0 < 2.0.3-1 | 2.0.3-1 |
| wordpress | wordpress | >= 0 < 2.0.3-1 | 2.0.3-1 |
| wordpress | wordpress | >= 0 < 2.0.3-1 | 2.0.3-1 |
| wordpress | wordpress | >= 0 < 2.0.3-1 | 2.0.3-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2006-2702: wordpress - vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote at...
vendor_debian·2006·CVSS 5.0
CVE-2006-2702 [MEDIUM] CVE-2006-2702: wordpress - vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote at...
vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].
Scope: local
bookworm: resolved (fixed in 2.0.3-1)
bullseye: resolved (fixed in 2.0.3-1)
forky: resolved (fixed in 2.0.3-1)
sid: resolved (fixed in 2.0.3-1)
trixie: resolved (fixed in 2.0.3-1)
GHSA
GHSA-x43j-vqrc-93c4: vars
ghsa_unreviewed·2022-05-01
CVE-2006-2702 [MEDIUM] GHSA-x43j-vqrc-93c4: vars
vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].
OSV
CVE-2006-2702: vars
osv·2006-05-31·CVSS 5.0
CVE-2006-2702 [MEDIUM] CVE-2006-2702: vars
vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://retrogod.altervista.org/wordpress_202_xpl.htmlhttp://secunia.com/advisories/20271http://secunia.com/advisories/20608http://www.gentoo.org/security/en/glsa/glsa-200606-08.xmlhttp://www.osvdb.org/25935http://www.securityfocus.com/archive/1/435039/100/0/threadedhttp://www.vupen.com/english/advisories/2006/1992https://exchange.xforce.ibmcloud.com/vulnerabilities/26688http://retrogod.altervista.org/wordpress_202_xpl.htmlhttp://secunia.com/advisories/20271http://secunia.com/advisories/20608http://www.gentoo.org/security/en/glsa/glsa-200606-08.xmlhttp://www.osvdb.org/25935http://www.securityfocus.com/archive/1/435039/100/0/threadedhttp://www.vupen.com/english/advisories/2006/1992https://exchange.xforce.ibmcloud.com/vulnerabilities/26688
2006-05-31
Published