Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"
Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

4.25.05.15.22023202420252026202720282029

Недавние уязвимости Django

Количество 673

nvd логотип

CVE-2016-2513

около 9 лет назад

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2016-2513

около 9 лет назад

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2016-2512

около 9 лет назад

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com\@attacker.com.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2016-2512

около 9 лет назад

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x ...

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2016-2513

около 9 лет назад

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2016-2512

около 9 лет назад

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com\@attacker.com.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2016-2513

больше 9 лет назад

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2016-2512

больше 9 лет назад

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com\@attacker.com.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2016-2048

больше 9 лет назад

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2016-2048

больше 9 лет назад

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, all ...

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2016-2513

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

CVSS3: 3.1
1%
Низкий
около 9 лет назад
debian логотип
CVE-2016-2513

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 ...

CVSS3: 3.1
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-2512

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com\@attacker.com.

CVSS3: 7.4
1%
Низкий
около 9 лет назад
debian логотип
CVE-2016-2512

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x ...

CVSS3: 7.4
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-2513

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

CVSS3: 3.1
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-2512

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com\@attacker.com.

CVSS3: 7.4
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2016-2513

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

CVSS2: 4.3
1%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-2512

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com\@attacker.com.

CVSS2: 5.8
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2048

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

CVSS3: 5.5
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2048

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, all ...

CVSS3: 5.5
0%
Низкий
больше 9 лет назад

Уязвимостей на страницу


Поделиться