← Back

CVE-2020-8984

nvd nist
Published: Mar 24, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.

Affected (123)

Products: Zend: Zendto
1 product
Zendto
Configuration A
123 vulnerable
Vulnerable SoftwareAffected Versions
Zend
Version 3.10
Version 3.11
Version 3.12
Version 3.13
Version 3.20
Version 3.51
Version 3.52
Version 3.53
Version 3.54
Version 3.55
Version 3.56-2
Version 3.57
Version 3.58
Version 3.59
Version 3.60
Version 3.61
Version 3.62
Version 3.63
Version 3.64
Version 3.65
Version 3.70-2
Version 3.71
Version 3.72
Version 3.73
Version 3.74
Version 3.75
Version 3.90
Version 3.91
Version 3.92
Version 3.93
Version 3.94
Version 4.00
Version 4.01
Version 4.02
Version 4.03-3
Version 4.05-2
Version 4.06-2
Version 4.07-1
Version 4.08-4
Version 4.09-1
Version 4.10-4
Version 4.10-5
Version 4.11-10
Version 4.11-11
Version 4.11-12
Version 4.11-13
Version 4.11-14
Version 4.11-1
Version 4.11-2
Version 4.11-3
Version 4.11-4
Version 4.11-5
Version 4.11-7
Version 4.11-8
Version 4.11-9
Version 4.12-5
Version 4.12-6
Version 4.13-1
Version 4.20-2
Version 4.20-3
Version 4.20-5
Version 4.20-6
Version 4.20-7
Version 4.25-3
Version 4.27-1
Version 4.27-2
Version 4.27-4
Version 4.27-5
Version 4.27-6
Version 4.27-7
Version 4.28-1
Version 4.28-2
Version 5.00-1
Version 5.00-2
Version 5.01-5
Version 5.02-5
Version 5.03-1
Version 5.04-7
Version 5.09-13
Version 5.10-1
Version 5.10-2
Version 5.11-1
Version 5.11-2
Version 5.11-3
Version 5.11-4
Version 5.11-5
Version 5.11-6
Version 5.12-3 beta
Version 5.12-4 beta
Version 5.12-6 beta
Version 5.12-7 beta
Version 5.12-8 beta
Version 5.13-1
Version 5.13-2
Version 5.14-2 beta
Version 5.14-5 beta
Version 5.15-1
Version 5.16-1 beta
Version 5.16-4 beta
Version 5.16-5 beta
Version 5.16-7 beta
Version 5.16-8 beta
Version 5.16.6 beta
Version 5.17-1
Version 5.17-2
Version 5.17-3
Version 5.17-4
Version 5.17-5 beta
Version 5.17-6
Version 5.18-1 beta
Version 5.18-2 beta
Version 5.19-1 production
Version 5.20-1 beta
Version 5.20-2 beta
Version 5.20-3 beta
Version 5.20-5 beta
Version 5.20-6 beta
Version 5.20-7 beta
Version 5.20-8 beta
Version 5.20-9 beta
Version 5.21-1 production
Version 5.21-2 production
Version 5.22-1 beta

References (4)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.