Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wqjj-hx84-v449

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.1
CVSS3: 9.8

Описание

Django Vulnerable to MySQL Injection

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

< 1.4.11

1.4.11

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.5, < 1.5.6

1.5.6

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.6, < 1.6.3

1.6.3

EPSS

Процентиль: 89%
0.05232
Низкий

8.1 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

ubuntu
около 11 лет назад

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

redhat
около 11 лет назад

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

nvd
около 11 лет назад

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

debian
около 11 лет назад

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressFie ...

EPSS

Процентиль: 89%
0.05232
Низкий

8.1 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-89