Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"
Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

4.25.05.15.22023202420252026202720282029

Недавние уязвимости Django

Количество 673

redhat логотип

CVE-2015-0221

больше 10 лет назад

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-0220

больше 10 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-0219

больше 10 лет назад

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2014-0483

почти 11 лет назад

The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field parameter in a popup action to an admin change form page, as demonstrated by a /admin/auth/user/?pop=1&t=password URI.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2014-0483

почти 11 лет назад

The administrative interface (contrib.admin) in Django before 1.4.14, ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2014-0482

почти 11 лет назад

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors related to the REMOTE_USER header.

CVSS2: 6
EPSS: Низкий
debian логотип

CVE-2014-0482

почти 11 лет назад

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django ...

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2014-0481

почти 11 лет назад

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-0481

почти 11 лет назад

The default configuration for the file upload handling system in Djang ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-0480

почти 11 лет назад

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.

CVSS2: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2015-0221

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 4.3
9%
Низкий
больше 10 лет назад
redhat логотип
CVE-2015-0220

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
2%
Низкий
больше 10 лет назад
redhat логотип
CVE-2015-0219

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

CVSS2: 5.8
4%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-0483

The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field parameter in a popup action to an admin change form page, as demonstrated by a /admin/auth/user/?pop=1&t=password URI.

CVSS2: 3.5
0%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-0483

The administrative interface (contrib.admin) in Django before 1.4.14, ...

CVSS2: 3.5
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-0482

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors related to the REMOTE_USER header.

CVSS2: 6
1%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-0482

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django ...

CVSS2: 6
1%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-0481

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

CVSS2: 4.3
1%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-0481

The default configuration for the file upload handling system in Djang ...

CVSS2: 4.3
1%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-0480

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.

CVSS2: 5.8
0%
Низкий
почти 11 лет назад

Уязвимостей на страницу


Поделиться