CWE-348: Use of Less Trusted Source
Use of Less Trusted Source
Weakness ID: 348 (Weakness Base) Status: Draft
Description
Description Summary
The software has two different sources of the same data or
information, but it uses the source that has less support for verification, is
less trusted, or is less resistant to attack.
Time of Introduction
Architecture and Design
Implementation
Observed Examples
Reference Description
CVE-2001-0860 Product uses IP address provided by a client,
instead of obtaining it from the packet headers, allowing easier
spoofing.
CVE-2004-1950 Web product uses the IP address in the
X-Forwarded-For HTTP header instead of a server variable that uses the
connecting IP address, allowing filter
bypass.
BID:15326 Similar to
CVE-2004-1950
CVE-2001-0908 Product logs IP address specified by the client
instead of obtaining it from the packet headers, allowing information
hiding.
CVE-2006-1126 PHP application uses IP address from
X-Forwarded-For HTTP header, instead of
REMOTE ADDR.
Relationships
Taxonomy Mappings
Mapped Taxonomy Name Node ID Fit Mapped Node Name
PLOVER Use of Less Trusted Source
Content History
Submissions Submission Date Submitter Organization Source PLOVER Externally Mined Modifications Modification Date Modifier Organization Source 2008-07-01 Eric Dalci Cigital External updated Time of Introduction 2008-09-08 CWE Content Team MITRE Internal updated Relationships,
Taxonomy Mappings