İçeriğe atla
Noroxi

web2py kayıtları

web2py üreticisine ait 13 yayımlanmış kayıt.

Tüm kayıtlar

13 kayıt
  • CVE-2016-3957
    40Planlayın

    The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, w

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    web2py · web2py6 Şub 2018

  • CVE-2023-45158
    40Planlayın

    An OS command injection vulnerability exists in web2py 2.24.1 and earlier.

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    web2py · web2py16 Eki 2023

  • CVE-2016-3953
    40Planlayın

    The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a har

    KritikCVSS 9,8İstismar yokEPSS %3

    web2py · web2py6 Şub 2018

  • CVE-2016-10321
    40Planlayın

    web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-for

    KritikCVSS 9,8İstismar yokEPSS %3

    web2py · web2py10 Nis 2017

  • CVE-2016-4808
    36İzleyin

    Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged

    YüksekCVSS 8,8Kavram kanıtıEPSS %2

    web2py · web2py11 Oca 2017

  • CVE-2016-4806
    33İzleyin

    Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access w

    YüksekCVSS 7,5Kavram kanıtıEPSS %10

    web2py · web2py11 Oca 2017

  • CVE-2016-3952
    31İzleyin

    web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request

    YüksekCVSS 7,8İstismar yokEPSS %1

    web2py · web2py6 Şub 2018

  • CVE-2023-22432
    25İzleyin

    Open redirect vulnerability exists in web2py versions prior to 2.23.1.

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    web2py · web2py5 Mar 2023

  • CVE-2022-33146
    24İzleyin

    Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and cond

    OrtaCVSS 6,1İstismar yokEPSS %2

    web2py · web2py26 Haz 2022

  • CVE-2015-6961
    24İzleyin

    Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct

    OrtaCVSS 6,1İstismar yokEPSS %1

    web2py · web2py18 Eki 2017

  • CVE-2016-3954
    22İzleyin

    web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status.

    OrtaCVSS 5,5İstismar yokEPSS %1

    web2py · web2py6 Şub 2018

  • CVE-2016-4807
    20İzleyin

    Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in

    OrtaCVSS 4,8Kavram kanıtıEPSS %2

    web2py · web2py11 Oca 2017

  • CVE-2013-2311
    17İzleyin

    Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote atta

    OrtaCVSS 4,3İstismar yokEPSS %1

    web2py · web2py22 May 2013