PT-2018-4909 · Web2Py+1 · Web2Py+1

Shaolin

·

Publicado

2018-02-06

·

Atualizado

2022-05-14

·

CVE-2016-3953

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions web2py versions prior to 2.14.2
Description The issue allows remote attackers to execute arbitrary code via vectors involving the use of a hardcoded encryption key when calling the session.connect function. This could potentially lead to unauthorized access and control of the system.
Recommendations For versions prior to 2.14.2, update to version 2.14.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the session.connect function until a patch is available.

Exploit

Correção

RCE

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-3953
GHSA-Q2RQ-QGCF-M22W
USN-4030-1

Produtos afetados

Ubuntu
Web2Py