PT-2018-4909 · Web2Py+1 · Web2Py+1

Shaolin

·

Published

2018-02-06

·

Updated

2022-05-14

·

CVE-2016-3953

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions web2py versions prior to 2.14.2
Description The issue allows remote attackers to execute arbitrary code via vectors involving the use of a hardcoded encryption key when calling the session.connect function. This could potentially lead to unauthorized access and control of the system.
Recommendations For versions prior to 2.14.2, update to version 2.14.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the session.connect function until a patch is available.

Exploit

Fix

RCE

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-3953
GHSA-Q2RQ-QGCF-M22W
USN-4030-1

Affected Products

Ubuntu
Web2Py