Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-0697

Опубликовано: 14 фев. 2011
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 might allow remote attackers to inject arbitrary web script or HTML via a filename associated with a file upload.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-djangofixed1.2.5-1package
python-djangonot-affectedlennypackage
python-djangofixed1.2.3-3+squeeze1squeezepackage

Примечания

  • http://www.djangoproject.com/weblog/2011/feb/08/security/

EPSS

Процентиль: 86%
0.02962
Низкий

Связанные уязвимости

ubuntu
больше 14 лет назад

Cross-site scripting (XSS) vulnerability in Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 might allow remote attackers to inject arbitrary web script or HTML via a filename associated with a file upload.

nvd
больше 14 лет назад

Cross-site scripting (XSS) vulnerability in Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 might allow remote attackers to inject arbitrary web script or HTML via a filename associated with a file upload.

CVSS3: 6.1
github
почти 7 лет назад

Cross-site scripting in django

EPSS

Процентиль: 86%
0.02962
Низкий