📦 Web2py

by Web2py

🔍 What is Web2py?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2016-3953

CRITICAL CVSS 9.8 Feb 6, 2018

This vulnerability in web2py's sample web application allows remote attackers to execute arbitrary code by exploiting a hardcoded encryption key in the session.connect function. Attackers can achieve ...

CVE-2016-3957

CRITICAL CVSS 9.8 Feb 6, 2018

This vulnerability allows remote attackers to execute arbitrary code on web2py applications by exploiting insecure deserialization of session cookies. Attackers can craft malicious cookies that, when ...

CVE-2016-10321

CRITICAL CVSS 9.8 Apr 10, 2017

This vulnerability in web2py allows remote attackers to bypass host-based access restrictions and perform brute-force password attacks against login systems. It affects web2py applications that use ho...

CVE-2016-3952

HIGH CVSS 7.8 Feb 6, 2018

This vulnerability in web2py allows remote attackers to read environment variables via direct access to the beautify example file. When combined with CVE-2016-3957, this information disclosure can be ...