Vulnerabilities
Vulnerable Software
Web2py:  >> Web2py  >> 2.18.5  Security Vulnerabilities
An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product.
CVSS Score
9.8
EPSS Score
0.15
Published
2023-10-16
Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.
CVSS Score
6.1
EPSS Score
0.513
Published
2023-03-06
Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
CVSS Score
6.1
EPSS Score
0.012
Published
2022-06-27


Contact Us

Shodan ® - All rights reserved