Description
The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a hardcoded encryption key when calling the session.connect function.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4863 | The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a hardcoded encryption key when calling the session.connect function. |
Github GHSA |
GHSA-q2rq-qgcf-m22w | web2py remote code execution via hardcoded encryption key in session.connect function |
Ubuntu USN |
USN-4030-1 | web2py vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T00:10:31.906Z
Reserved: 2016-04-05T00:00:00.000Z
Link: CVE-2016-3953
No data.
Status : Modified
Published: 2018-02-06T18:29:00.273
Modified: 2024-11-21T02:51:01.280
Link: CVE-2016-3953
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA
Ubuntu USN