Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3952

Опубликовано: 06 фев. 2018
Источник: debian

Описание

web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request to examples/template_examples/beautify. NOTE: this issue can be leveraged by remote attackers to gain administrative access.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
web2pyremovedpackage
web2pynot-affectedjessiepackage
web2pynot-affectedwheezypackage

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 8 лет назад

web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request to examples/template_examples/beautify. NOTE: this issue can be leveraged by remote attackers to gain administrative access.

CVSS3: 7.8
nvd
около 8 лет назад

web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request to examples/template_examples/beautify. NOTE: this issue can be leveraged by remote attackers to gain administrative access.

CVSS3: 7.8
github
больше 3 лет назад

web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request to examples/template_examples/beautify. NOTE: this issue can be leveraged by remote attackers to gain administrative access.