Описание
The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 1.4.2-1 |
hardy | ignored | end of life |
lucid | released | 1.1.1-2ubuntu1.6 |
oneiric | released | 1.3-2ubuntu1.4 |
precise | released | 1.3.1-4ubuntu1.3 |
quantal | released | 1.4.1-2ubuntu0.1 |
upstream | released | 1.4.2-1 |
Показывать по
Ссылки на источники
EPSS
6.4 Medium
CVSS2
Связанные уязвимости
The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.
The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.
The django.http.HttpRequest.get_host function in Django 1.3.x before 1 ...
EPSS
6.4 Medium
CVSS2