7.5
CVSSv2

CVE-2016-3953

Published: 06/02/2018 Updated: 21/06/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The sample web application in web2py prior to 2.14.2 might allow remote malicious users to execute arbitrary code via vectors involving use of a hardcoded encryption key when calling the session.connect function.

Vulnerable Product Search on Vulmon Subscribe to Product

web2py web2py

Vendor Advisories

Several security issues were fixed in web2py ...
Debian Bug report logs - #891220 web2py: CVE-2016-3952 CVE-2016-3953 CVE-2016-3954 CVE-2016-3957 Package: src:web2py; Maintainer for src:web2py is José L Redrejo Rodríguez <jredrejo@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 23 Feb 2018 14:09:02 UTC Severity: grave Tags: fixed-up ...