web2py kayıtları
web2py üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %46,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-502 Deserialization of Untrusted Data1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2016-3957Kavram kanıtı | The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, wweb2py · web2py · CWE-502 | Kritik9,8 | — | %4,9 | 6 Şub 2018 |
40Planlayın | CVE-2023-45158Kavram kanıtı | An OS command injection vulnerability exists in web2py 2.24.1 and earlier.web2py · web2py · CWE-78 | Kritik9,8 | — | %3,7 | 16 Eki 2023 |
40Planlayın | CVE-2016-3953İstismar yok | The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a harweb2py · web2py · CWE-798 | Kritik9,8 | — | %3,3 | 6 Şub 2018 |
40Planlayın | CVE-2016-10321İstismar yok | web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-forweb2py · web2py · CWE-254 | Kritik9,8 | — | %2,6 | 10 Nis 2017 |
36İzleyin | CVE-2016-4808Kavram kanıtı | Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a loggedweb2py · web2py · CWE-352 | Yüksek8,8 | — | %1,8 | 11 Oca 2017 |
33İzleyin | CVE-2016-4806Kavram kanıtı | Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access wweb2py · web2py · CWE-200 | Yüksek7,5 | — | %10,1 | 11 Oca 2017 |
31İzleyin | CVE-2016-3952İstismar yok | web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request web2py · web2py · CWE-255 | Yüksek7,8 | — | %1,1 | 6 Şub 2018 |
25İzleyin | CVE-2023-22432Kavram kanıtı | Open redirect vulnerability exists in web2py versions prior to 2.23.1.web2py · web2py · CWE-601 | Orta6,1 | — | %2,4 | 5 Mar 2023 |
24İzleyin | CVE-2022-33146İstismar yok | Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and condweb2py · web2py · CWE-601 | Orta6,1 | — | %1,6 | 26 Haz 2022 |
24İzleyin | CVE-2015-6961İstismar yok | Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct web2py · web2py · CWE-601 | Orta6,1 | — | %1,0 | 18 Eki 2017 |
22İzleyin | CVE-2016-3954İstismar yok | web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status.web2py · web2py · CWE-200 | Orta5,5 | — | %1,4 | 6 Şub 2018 |
20İzleyin | CVE-2016-4807Kavram kanıtı | Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged inweb2py · web2py · CWE-79 | Orta4,8 | — | %2,3 | 11 Oca 2017 |
17İzleyin | CVE-2013-2311İstismar yok | Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote attaweb2py · web2py · CWE-79 | Orta4,3 | — | %1,2 | 22 May 2013 |
- CVE-2016-395740Planlayın
The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, w
KritikCVSS 9,8Kavram kanıtıEPSS %5web2py · web2py6 Şub 2018
- CVE-2023-4515840Planlayın
An OS command injection vulnerability exists in web2py 2.24.1 and earlier.
KritikCVSS 9,8Kavram kanıtıEPSS %4web2py · web2py16 Eki 2023
- CVE-2016-395340Planlayın
The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a har
KritikCVSS 9,8İstismar yokEPSS %3web2py · web2py6 Şub 2018
- CVE-2016-1032140Planlayın
web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-for
KritikCVSS 9,8İstismar yokEPSS %3web2py · web2py10 Nis 2017
- CVE-2016-480836İzleyin
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged
YüksekCVSS 8,8Kavram kanıtıEPSS %2web2py · web2py11 Oca 2017
- CVE-2016-480633İzleyin
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access w
YüksekCVSS 7,5Kavram kanıtıEPSS %10web2py · web2py11 Oca 2017
- CVE-2016-395231İzleyin
web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request
YüksekCVSS 7,8İstismar yokEPSS %1web2py · web2py6 Şub 2018
- CVE-2023-2243225İzleyin
Open redirect vulnerability exists in web2py versions prior to 2.23.1.
OrtaCVSS 6,1Kavram kanıtıEPSS %2web2py · web2py5 Mar 2023
- CVE-2022-3314624İzleyin
Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and cond
OrtaCVSS 6,1İstismar yokEPSS %2web2py · web2py26 Haz 2022
- CVE-2015-696124İzleyin
Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct
OrtaCVSS 6,1İstismar yokEPSS %1web2py · web2py18 Eki 2017
- CVE-2016-395422İzleyin
web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status.
OrtaCVSS 5,5İstismar yokEPSS %1web2py · web2py6 Şub 2018
- CVE-2016-480720İzleyin
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in
OrtaCVSS 4,8Kavram kanıtıEPSS %2web2py · web2py11 Oca 2017
- CVE-2013-231117İzleyin
Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote atta
OrtaCVSS 4,3İstismar yokEPSS %1web2py · web2py22 May 2013