Vulnerabilities
Vulnerable Software
Phpipam:  >> Phpipam  >> 1.5.0  Security Vulnerabilities
phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X-Forwarded-For' header. The issue lies in the 'get_user_ip()' function in 'class.Common.php' at lines 1044 and 1045, where the presence of the 'X-Forwarded-For' header is checked and used instead of 'REMOTE_ADDR'. This vulnerability allows attackers to perform brute force attacks on user accounts, including the admin account. The issue is fixed in version 1.7.0.
CVSS Score
5.3
EPSS Score
0.0
Published
2024-11-15
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.
CVSS Score
7.5
EPSS Score
0.006
Published
2023-10-02
SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
CVSS Score
7.2
EPSS Score
0.003
Published
2023-03-07
Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-03-07
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.
CVSS Score
2.4
EPSS Score
0.005
Published
2023-02-04
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.
CVSS Score
4.4
EPSS Score
0.001
Published
2023-02-04
Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
CVSS Score
7.5
EPSS Score
0.64
Published
2023-02-04
phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.
CVSS Score
9.8
EPSS Score
0.015
Published
2022-10-03


Contact Us

Shodan ® - All rights reserved