VendorsRuby on Railsweb_consoleany version
Vulnerabilities

Ruby on Rails Web Console any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2015-3224
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.
Published 2015-07-26 · Modified
4.31 PoCEPSS 0.447