web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request to examples/template_examples/beautify. NOTE: this issue can be leveraged by remote attackers to gain administrative access.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Web2py | Web2py | * | 2.14.1 (excluding) |
Web2py | Ubuntu | artful | * |
Web2py | Ubuntu | xenial | * |