CVE-2016-3954: Infoleak
Last updated 25 August 2025
Other sources
web2py before 2.14.2 allows remote attackers to obtain the sessioncookiekey value via a direct request to examples/simpleexamples/status. NOTE: this issue can be leveraged by remote attackers to execute arbitrary code using CVE-2016-3957.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-3954?
CVE-2016-3954 refers to a vulnerability in web2py before 2.14.2 that allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status.
What is the severity of CVE-2016-3954?
CVE-2016-3954 has a severity value of 5.5 out of 10, making it a medium severity vulnerability.
How can CVE-2016-3954 be exploited?
CVE-2016-3954 can be leveraged by remote attackers to obtain the session_cookie_key value and potentially execute arbitrary code using CVE-2016-3957.
What is the affected software for CVE-2016-3954?
The affected software for CVE-2016-3954 includes web2py versions before 2.14.2.
Are there any remedies or fixes for CVE-2016-3954?
Yes, the recommended remedy for CVE-2016-3954 is to update web2py to version 2.14.2 or apply the provided patches from the relevant sources.