lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
2020-03-24T21:15:15.393
2024-11-21T05:39:46.643
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zend | zendto | 3.10 | Yes |
Application | zend | zendto | 3.11 | Yes |
Application | zend | zendto | 3.12 | Yes |
Application | zend | zendto | 3.13 | Yes |
Application | zend | zendto | 3.20 | Yes |
Application | zend | zendto | 3.51 | Yes |
Application | zend | zendto | 3.52 | Yes |
Application | zend | zendto | 3.53 | Yes |
Application | zend | zendto | 3.54 | Yes |
Application | zend | zendto | 3.55 | Yes |
Application | zend | zendto | 3.56-2 | Yes |
Application | zend | zendto | 3.57 | Yes |
Application | zend | zendto | 3.58 | Yes |
Application | zend | zendto | 3.59 | Yes |
Application | zend | zendto | 3.60 | Yes |
Application | zend | zendto | 3.61 | Yes |
Application | zend | zendto | 3.62 | Yes |
Application | zend | zendto | 3.63 | Yes |
Application | zend | zendto | 3.64 | Yes |
Application | zend | zendto | 3.65 | Yes |
Application | zend | zendto | 3.70-2 | Yes |
Application | zend | zendto | 3.71 | Yes |
Application | zend | zendto | 3.72 | Yes |
Application | zend | zendto | 3.73 | Yes |
Application | zend | zendto | 3.74 | Yes |
Application | zend | zendto | 3.75 | Yes |
Application | zend | zendto | 3.90 | Yes |
Application | zend | zendto | 3.91 | Yes |
Application | zend | zendto | 3.92 | Yes |
Application | zend | zendto | 3.93 | Yes |
Application | zend | zendto | 3.94 | Yes |
Application | zend | zendto | 4.00 | Yes |
Application | zend | zendto | 4.01 | Yes |
Application | zend | zendto | 4.02 | Yes |
Application | zend | zendto | 4.03-3 | Yes |
Application | zend | zendto | 4.05-2 | Yes |
Application | zend | zendto | 4.06-2 | Yes |
Application | zend | zendto | 4.07-1 | Yes |
Application | zend | zendto | 4.08-4 | Yes |
Application | zend | zendto | 4.09-1 | Yes |
Application | zend | zendto | 4.10-4 | Yes |
Application | zend | zendto | 4.10-5 | Yes |
Application | zend | zendto | 4.11-1 | Yes |
Application | zend | zendto | 4.11-2 | Yes |
Application | zend | zendto | 4.11-3 | Yes |
Application | zend | zendto | 4.11-4 | Yes |
Application | zend | zendto | 4.11-5 | Yes |
Application | zend | zendto | 4.11-7 | Yes |
Application | zend | zendto | 4.11-8 | Yes |
Application | zend | zendto | 4.11-9 | Yes |
Application | zend | zendto | 4.11-10 | Yes |
Application | zend | zendto | 4.11-11 | Yes |
Application | zend | zendto | 4.11-12 | Yes |
Application | zend | zendto | 4.11-13 | Yes |
Application | zend | zendto | 4.11-14 | Yes |
Application | zend | zendto | 4.12-5 | Yes |
Application | zend | zendto | 4.12-6 | Yes |
Application | zend | zendto | 4.13-1 | Yes |
Application | zend | zendto | 4.20-2 | Yes |
Application | zend | zendto | 4.20-3 | Yes |
Application | zend | zendto | 4.20-5 | Yes |
Application | zend | zendto | 4.20-6 | Yes |
Application | zend | zendto | 4.20-7 | Yes |
Application | zend | zendto | 4.25-3 | Yes |
Application | zend | zendto | 4.27-1 | Yes |
Application | zend | zendto | 4.27-2 | Yes |
Application | zend | zendto | 4.27-4 | Yes |
Application | zend | zendto | 4.27-5 | Yes |
Application | zend | zendto | 4.27-6 | Yes |
Application | zend | zendto | 4.27-7 | Yes |
Application | zend | zendto | 4.28-1 | Yes |
Application | zend | zendto | 4.28-2 | Yes |
Application | zend | zendto | 5.00-1 | Yes |
Application | zend | zendto | 5.00-2 | Yes |
Application | zend | zendto | 5.01-5 | Yes |
Application | zend | zendto | 5.02-5 | Yes |
Application | zend | zendto | 5.03-1 | Yes |
Application | zend | zendto | 5.04-7 | Yes |
Application | zend | zendto | 5.09-13 | Yes |
Application | zend | zendto | 5.10-1 | Yes |
Application | zend | zendto | 5.10-2 | Yes |
Application | zend | zendto | 5.11-1 | Yes |
Application | zend | zendto | 5.11-2 | Yes |
Application | zend | zendto | 5.11-3 | Yes |
Application | zend | zendto | 5.11-4 | Yes |
Application | zend | zendto | 5.11-5 | Yes |
Application | zend | zendto | 5.11-6 | Yes |
Application | zend | zendto | 5.12-3 | Yes |
Application | zend | zendto | 5.12-4 | Yes |
Application | zend | zendto | 5.12-6 | Yes |
Application | zend | zendto | 5.12-7 | Yes |
Application | zend | zendto | 5.12-8 | Yes |
Application | zend | zendto | 5.13-1 | Yes |
Application | zend | zendto | 5.13-2 | Yes |
Application | zend | zendto | 5.14-2 | Yes |
Application | zend | zendto | 5.14-5 | Yes |
Application | zend | zendto | 5.15-1 | Yes |
Application | zend | zendto | 5.16-1 | Yes |
Application | zend | zendto | 5.16-4 | Yes |
Application | zend | zendto | 5.16-5 | Yes |
Application | zend | zendto | 5.16-7 | Yes |
Application | zend | zendto | 5.16-8 | Yes |
Application | zend | zendto | 5.16.6 | Yes |
Application | zend | zendto | 5.17-1 | Yes |
Application | zend | zendto | 5.17-2 | Yes |
Application | zend | zendto | 5.17-3 | Yes |
Application | zend | zendto | 5.17-4 | Yes |
Application | zend | zendto | 5.17-5 | Yes |
Application | zend | zendto | 5.17-6 | Yes |
Application | zend | zendto | 5.18-1 | Yes |
Application | zend | zendto | 5.18-2 | Yes |
Application | zend | zendto | 5.19-1 | Yes |
Application | zend | zendto | 5.20-1 | Yes |
Application | zend | zendto | 5.20-2 | Yes |
Application | zend | zendto | 5.20-3 | Yes |
Application | zend | zendto | 5.20-5 | Yes |
Application | zend | zendto | 5.20-6 | Yes |
Application | zend | zendto | 5.20-7 | Yes |
Application | zend | zendto | 5.20-8 | Yes |
Application | zend | zendto | 5.20-9 | Yes |
Application | zend | zendto | 5.21-1 | Yes |
Application | zend | zendto | 5.21-2 | Yes |
Application | zend | zendto | 5.22-1 | Yes |