Critical severity9.8NVD Advisory· Published Feb 6, 2018· Updated Jun 17, 2026
CVE-2016-3953
CVE-2016-3953
Description
The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a hardcoded encryption key when calling the session.connect function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
web2pyPyPI | < 2.14.2 | 2.14.2 |
Affected products
1Patches
Vulnerability mechanics
References
9- devco.re/blog/2017/01/03/web2py-unserialize-code-execution-CVE-2016-3957/nvdExploitTechnical DescriptionThird Party Advisory
- github.com/advisories/GHSA-q2rq-qgcf-m22wghsaADVISORY
- github.com/web2py/web2py/blob/R-2.14.1/applications/examples/models/session.pynvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2016-3953ghsaADVISORY
- devco.re/blog/2017/01/03/web2py-unserialize-code-execution-CVE-2016-3957ghsaWEB
- github.com/web2py/web2py/commit/9706d125b42481178d2b423de245f5d2faadbf40ghsaWEB
- github.com/web2py/web2py/issues/1205ghsaWEB
- usn.ubuntu.com/4030-1ghsaWEB
- usn.ubuntu.com/4030-1/nvd
News mentions
0No linked articles in our index yet.