Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-4249

Опубликовано: 04 окт. 2013
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before 1.6 beta 2 allows remote attackers to inject arbitrary web script or HTML via a URLField.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-djangofixed1.5.2-1package
python-djangonot-affectedwheezypackage
python-djangonot-affectedsqueezepackage

Примечания

  • problem introduced with https://github.com/django/django/commit/ac2052ebc84c45709ab5f0f25e685bf656ce79bc

EPSS

Процентиль: 35%
0.00142
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before 1.6 beta 2 allows remote attackers to inject arbitrary web script or HTML via a URLField.

nvd
больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before 1.6 beta 2 allows remote attackers to inject arbitrary web script or HTML via a URLField.

CVSS3: 6.1
github
около 3 лет назад

Django cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget

EPSS

Процентиль: 35%
0.00142
Низкий