Description
This directory normally returns a 403 Forbidden HTTP status code. Acunetix managed to bypass this restriction by spoofing the "X-Forwarded-For" HTTP header and set various internal IP addresses.
Remediation
X-Forwarded-For HTTP header should not be used for any Access Control List (ACL) checks because it can be spoofed by attackers. Use the real IP address for this type of restrictions.
References
Related Vulnerabilities
Frontpage authors.pwd available
WordPress Plugin wp superb Slideshow Information Disclosure (2.4)
WordPress Plugin Tutor LMS-eLearning and online course solution Security Bypass (2.7.0)
WordPress Plugin YITH WooCommerce Stripe Security Bypass (2.0.1)
WordPress Plugin YITH WooCommerce Ajax Search Security Bypass (1.6.9)