web2py是web2py开源的一个免费和开源的全栈企业框架。用于敏捷开发安全的数据库驱动的基于 Web 的应用程序。 web2py 2.23.1之前版本存在安全漏洞,该漏洞源于存在开放重定向漏洞,攻击者利用该漏洞可以通过让用户访问特制的URL重定向到任意网站。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | PoC for CVE-2023-22432 (web2py) | https://github.com/aeyesec/CVE-2023-22432 | POC Details |
| 2 | Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-22432.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet