← Back

CVE-2009-3287

nvd nist
Published: Sep 22, 2009Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to spoof the IP address and hide activities via a modified X-Forwarded-For header.

Affected (21)

Products: Macournoyer: Thin
1 product
Thin
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Macournoyer
Up to 1.2.2
Version 0.4.0
Version 0.4.1
Version 0.5.0
Version 0.5.1
Version 0.5.2
Version 0.5.3
Version 0.5.4
Version 0.6.0
Version 0.6.3
Version 0.6.4
Version 0.7.0
Version 0.7.1
Version 0.8.0
Version 0.8.1
Version 0.8.2
Version 1.0.0
Version 1.1.0
Version 1.1.1
Version 1.2.0
Version 1.2.1

Timeline

No history available yet.