Записи web2py
13 опубликованных записей вендора web2py.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 46,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-502 Deserialization of Untrusted Data1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2016-3957Proof of concept | The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, wweb2py · web2py · CWE-502 | Критическая9,8 | — | 4,9 % | 6 февр. 2018 г. |
40В плане | CVE-2023-45158Proof of concept | An OS command injection vulnerability exists in web2py 2.24.1 and earlier.web2py · web2py · CWE-78 | Критическая9,8 | — | 3,7 % | 16 окт. 2023 г. |
40В плане | CVE-2016-3953Эксплойта нет | The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a harweb2py · web2py · CWE-798 | Критическая9,8 | — | 3,3 % | 6 февр. 2018 г. |
40В плане | CVE-2016-10321Эксплойта нет | web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-forweb2py · web2py · CWE-254 | Критическая9,8 | — | 2,6 % | 10 апр. 2017 г. |
36Наблюдать | CVE-2016-4808Proof of concept | Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a loggedweb2py · web2py · CWE-352 | Высокая8,8 | — | 1,8 % | 11 янв. 2017 г. |
33Наблюдать | CVE-2016-4806Proof of concept | Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access wweb2py · web2py · CWE-200 | Высокая7,5 | — | 10,1 % | 11 янв. 2017 г. |
31Наблюдать | CVE-2016-3952Эксплойта нет | web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request web2py · web2py · CWE-255 | Высокая7,8 | — | 1,1 % | 6 февр. 2018 г. |
25Наблюдать | CVE-2023-22432Proof of concept | Open redirect vulnerability exists in web2py versions prior to 2.23.1.web2py · web2py · CWE-601 | Средняя6,1 | — | 2,4 % | 5 мар. 2023 г. |
24Наблюдать | CVE-2022-33146Эксплойта нет | Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and condweb2py · web2py · CWE-601 | Средняя6,1 | — | 1,6 % | 26 июн. 2022 г. |
24Наблюдать | CVE-2015-6961Эксплойта нет | Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct web2py · web2py · CWE-601 | Средняя6,1 | — | 1,0 % | 18 окт. 2017 г. |
22Наблюдать | CVE-2016-3954Эксплойта нет | web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status.web2py · web2py · CWE-200 | Средняя5,5 | — | 1,4 % | 6 февр. 2018 г. |
20Наблюдать | CVE-2016-4807Proof of concept | Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged inweb2py · web2py · CWE-79 | Средняя4,8 | — | 2,3 % | 11 янв. 2017 г. |
17Наблюдать | CVE-2013-2311Эксплойта нет | Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote attaweb2py · web2py · CWE-79 | Средняя4,3 | — | 1,2 % | 22 мая 2013 г. |
- CVE-2016-395740В плане
The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, w
КритическаяCVSS 9,8Proof of conceptEPSS 5 %web2py · web2py6 февр. 2018 г.
- CVE-2023-4515840В плане
An OS command injection vulnerability exists in web2py 2.24.1 and earlier.
КритическаяCVSS 9,8Proof of conceptEPSS 4 %web2py · web2py16 окт. 2023 г.
- CVE-2016-395340В плане
The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a har
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %web2py · web2py6 февр. 2018 г.
- CVE-2016-1032140В плане
web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-for
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %web2py · web2py10 апр. 2017 г.
- CVE-2016-480836Наблюдать
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %web2py · web2py11 янв. 2017 г.
- CVE-2016-480633Наблюдать
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access w
ВысокаяCVSS 7,5Proof of conceptEPSS 10 %web2py · web2py11 янв. 2017 г.
- CVE-2016-395231Наблюдать
web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %web2py · web2py6 февр. 2018 г.
- CVE-2023-2243225Наблюдать
Open redirect vulnerability exists in web2py versions prior to 2.23.1.
СредняяCVSS 6,1Proof of conceptEPSS 2 %web2py · web2py5 мар. 2023 г.
- CVE-2022-3314624Наблюдать
Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and cond
СредняяCVSS 6,1Эксплойта нетEPSS 2 %web2py · web2py26 июн. 2022 г.
- CVE-2015-696124Наблюдать
Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct
СредняяCVSS 6,1Эксплойта нетEPSS 1 %web2py · web2py18 окт. 2017 г.
- CVE-2016-395422Наблюдать
web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status.
СредняяCVSS 5,5Эксплойта нетEPSS 1 %web2py · web2py6 февр. 2018 г.
- CVE-2016-480720Наблюдать
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in
СредняяCVSS 4,8Proof of conceptEPSS 2 %web2py · web2py11 янв. 2017 г.
- CVE-2013-231117Наблюдать
Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote atta
СредняяCVSS 4,3Эксплойта нетEPSS 1 %web2py · web2py22 мая 2013 г.