Variable $_SERVER['HTTP_X_FORWARDED_FOR'] isn't properly sanitized. This
can be used to post HTTP query with fake X-Forwarded-For value which may
contain arbitrary html or script code. This code will be executed when
administrator will open "View all members" section in Administrator's
control panel .
Administrator's session is threatened.
--------------Exploit----------------------
Available at: http://evuln.com/vulns/86/exploit.html
--------------Solution---------------------
No Patch available.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.