CVE-2015-3224 is a vulnerability in Web Console (used with Ruby on Rails 3.x and 4.x) where the request.rb component fails to properly restrict the use of X-Forwarded-For headers when determining a client's IP address. This allows remote attackers to bypass the whitelisted_ips protection mechanism by sending crafted requests, potentially enabling remote code execution in environments where Web Console is enabled and accessible from remote IPs.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Node.js exploit script (CVE-2015-3224.js) targeting CVE-2015-3224, a remote code execution vulnerability in the Ruby on Rails 'web-console' gem (versions prior to 2.1.3). The exploit works by spoofing the 'X-Forwarded-For' header to bypass IP restrictions and gain access to the web console, which is intended for local debugging. The script first discovers the required session path by forcing a 404 error and parsing the debug page, then sends a crafted PUT request to the console endpoint with an arbitrary shell command. The output of the command is extracted and displayed to the user. The repository is structured with a single exploit script, a README detailing usage and vulnerability background, and a license file. The exploit is operational and provides unauthenticated RCE against vulnerable Rails applications exposed to the network.
This repository contains a Python exploit script (exploit.py) targeting CVE-2015-3224, an IP whitelist bypass vulnerability in the Ruby on Rails web console (versions 4.0.x and 4.1.x). The exploit abuses improper handling of the X-Forwarded-For HTTP header to spoof the attacker's IP as a trusted local address, thereby bypassing access controls and gaining unauthorized access to the developer web console. The script first probes the target for the dynamic web console path by triggering a routing error, then allows the attacker to execute arbitrary commands via the console. It supports two modes: a simple interactive shell for command execution, and a reverse shell mode that delivers a Python-based PTY reverse shell to the attacker's machine. The exploit requires the attacker to specify the target's base URL and, for reverse shell mode, the attacker's own IP and port for the callback. The repository consists of a README.md (detailed usage and vulnerability explanation) and the main exploit script (exploit.py). The attack vector is network-based, targeting accessible HTTP endpoints on vulnerable servers. No hardcoded IPs or domains are present; the script is designed for flexible targeting via user-supplied parameters.
This repository contains a single Metasploit module: 'rails_web_console_v2_code_exec.rb', which exploits CVE-2015-3224, an IP whitelist bypass vulnerability in the Ruby on Rails Web Console (v2) gem. The exploit targets Rails versions 4.0.x and 4.1.x (and 4.2.x if the attacker is on a whitelisted IP) by abusing the developer web console's IP filtering. The module works by first identifying the web console's path and session ID, then sending a specially crafted HTTP PUT request with a Metasploit payload (arbitrary Ruby code) to achieve remote code execution. The exploit is fully integrated into the Metasploit framework, allowing for customizable payloads and automated exploitation. The only fingerprintable endpoint is the configurable TARGETURI (default '/missing404'), which should point to a vulnerable Rails application. The code is mature and weaponized, suitable for real-world exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.