CVE-2016-4806: Infoleak
Published Jan 11, 2017
·Updated
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files.
Affected Software
1 affected component
Web2py Web2py<=2.14.5
Event History
Jan 11, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-4806?
CVE-2016-4806 is considered a medium severity vulnerability due to its potential to expose sensitive files on the web server.
2
How do I fix CVE-2016-4806?
To fix CVE-2016-4806, upgrade your Web2py installation to version 2.14.6 or later.
3
What versions of Web2py are affected by CVE-2016-4806?
Web2py versions 2.14.5 and below are affected by CVE-2016-4806.
4
What type of vulnerability is CVE-2016-4806?
CVE-2016-4806 is a Local File Inclusion vulnerability that allows unauthorized access to sensitive files.
5
Who can be impacted by CVE-2016-4806?
Any user with malicious intent can exploit CVE-2016-4806 to read sensitive files from a vulnerable Web2py server.