Skip to content
Noroxi

web2py records

13 published records for vendor web2py.

All records

13 records
  • The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, w

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    web2py · web2pyFeb 6, 2018

  • An OS command injection vulnerability exists in web2py 2.24.1 and earlier.

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    web2py · web2pyOct 16, 2023

  • The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a har

    CriticalCVSS 9.8No exploitEPSS 3%

    web2py · web2pyFeb 6, 2018

  • web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-for

    CriticalCVSS 9.8No exploitEPSS 3%

    web2py · web2pyApr 10, 2017

  • CVE-2016-4808
    36Monitor

    Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged

    HighCVSS 8.8Proof of conceptEPSS 2%

    web2py · web2pyJan 11, 2017

  • CVE-2016-4806
    33Monitor

    Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access w

    HighCVSS 7.5Proof of conceptEPSS 10%

    web2py · web2pyJan 11, 2017

  • CVE-2016-3952
    31Monitor

    web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request

    HighCVSS 7.8No exploitEPSS 1%

    web2py · web2pyFeb 6, 2018

  • Open redirect vulnerability exists in web2py versions prior to 2.23.1.

    MediumCVSS 6.1Proof of conceptEPSS 2%

    web2py · web2pyMar 5, 2023

  • Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and cond

    MediumCVSS 6.1No exploitEPSS 2%

    web2py · web2pyJun 26, 2022

  • CVE-2015-6961
    24Monitor

    Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct

    MediumCVSS 6.1No exploitEPSS 1%

    web2py · web2pyOct 18, 2017

  • CVE-2016-3954
    22Monitor

    web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status.

    MediumCVSS 5.5No exploitEPSS 1%

    web2py · web2pyFeb 6, 2018

  • CVE-2016-4807
    20Monitor

    Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in

    MediumCVSS 4.8Proof of conceptEPSS 2%

    web2py · web2pyJan 11, 2017

  • CVE-2013-2311
    17Monitor

    Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote atta

    MediumCVSS 4.3No exploitEPSS 1%

    web2py · web2pyMay 22, 2013