Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2011-3624

Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Server headers in requests, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 67.8%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2011-3624
  • Ruby-Lang » Ruby » Version: 1.8.7
    cpe:2.3:a:ruby-lang:ruby:1.8.7
  • Ruby-Lang » Ruby » Version: 1.9.2
    cpe:2.3:a:ruby-lang:ruby:1.9.2


Contact Us

Shodan ® - All rights reserved