J-Security Center

Title: Invision Power Board Potential IP Address Spoofing Vulnerability

Severity: MODERATE

Description:

Invision Board is web forum software. It is implemented in PHP and is available for Unix and Linux variants and Microsoft Windows operating systems.

It is reported that Invision Power Board is prone to an IP address spoofing vulnerability. This issue presents itself due to a design error in the application. Specifically, if an attacker is using a proxy to access a remote forum, the application logs the attacker's internal IP address on the LAN, instead of the real IP address of the proxy. This issue could potentially allow an attacker to spoof their IP address by using a proxy and carry out attacks without revealing their real IP address.

This issue is reported to affect Invision Power Board version 1.3, however, it is likely that other versions are affected as well.

Affected Products:

  • Invision Power Services Invision Board 1.3.0
  • Invision Power Services Invision Board 1.3.0 Final
  • Invision Power Services Invision Board 1.3.1 Final

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.