Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-4140

Опубликовано: 19 окт. 2011
Источник: ubuntu
Приоритет: negligible
CVSS2: 6.8

Описание

The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary HTTP Host headers, which allows remote attackers to trigger unauthenticated forged requests via vectors involving a DNS CNAME record and a web page containing JavaScript code.

РелизСтатусПримечание
devel

ignored

hardy

ignored

lucid

ignored

maverick

ignored

natty

ignored

oneiric

ignored

upstream

ignored

Показывать по

6.8 Medium

CVSS2

Связанные уязвимости

nvd
почти 14 лет назад

The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary HTTP Host headers, which allows remote attackers to trigger unauthenticated forged requests via vectors involving a DNS CNAME record and a web page containing JavaScript code.

debian
почти 14 лет назад

The CSRF protection mechanism in Django through 1.2.7 and 1.3.x throug ...

CVSS3: 7.5
github
около 7 лет назад

Django Cross-Site Request Forgery vulnerability

6.8 Medium

CVSS2