Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown
CVE-2016-4807
Disclosure Date: January 11, 2017 (last updated November 25, 2024)
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).
0
Attacker Value
Unknown
CVE-2016-4808
Disclosure Date: January 11, 2017 (last updated November 25, 2024)
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user to perform some unwanted actions i.e An attacker can trick an victim to disable the installed application just by sending a URL to victim.
0
Attacker Value
Unknown
CVE-2013-2311
Disclosure Date: May 22, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0