Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-2317

Опубликовано: 25 мар. 2015
Источник: debian
EPSS Низкий

Описание

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-djangofixed1.7.7-1package
python-djangono-dsasqueezepackage

Примечания

  • https://github.com/django/django/commit/2342693b31f740a422abf7267c53b4e7bc487c1b (1.4.x)

  • https://github.com/django/django/commit/2a4113dbd532ce952308992633d802dc169a75f1 (1.7.x)

EPSS

Процентиль: 86%
0.03149
Низкий

Связанные уязвимости

ubuntu
около 10 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

redhat
больше 10 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

nvd
около 10 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

CVSS3: 6.1
github
около 3 лет назад

Django cross-site scripting (XSS) attack via user-supplied redirect URLs

EPSS

Процентиль: 86%
0.03149
Низкий