Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-3287

Опубликовано: 22 сент. 2009
Источник: debian

Описание

lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to spoof the IP address and hide activities via a modified X-Forwarded-For header.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
thinfixed1.2.4-1package

Связанные уязвимости

nvd
больше 16 лет назад

lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to spoof the IP address and hide activities via a modified X-Forwarded-For header.

github
больше 8 лет назад

High severity vulnerability that affects thin