Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"
Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

4.25.05.15.26.02023202420252026202720282029

Недавние уязвимости Django

Количество 751

redhat логотип

CVE-2015-3982

больше 10 лет назад

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2015-2317

почти 11 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-2317

почти 11 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1. ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-2316

почти 11 лет назад

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-2316

почти 11 лет назад

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7. ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-2316

почти 11 лет назад

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-2317

почти 11 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-2316

почти 11 лет назад

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-2317

почти 11 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2015-2241

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2015-3982

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.

CVSS2: 5.8
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-2317

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

CVSS2: 4.3
5%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-2317

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1. ...

CVSS2: 4.3
5%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-2316

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 5
2%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-2316

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7. ...

CVSS2: 5
2%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-2316

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 5
2%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-2317

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

CVSS2: 4.3
5%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-2316

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 4.3
2%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-2317

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

CVSS2: 2.6
5%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-2241

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

CVSS2: 4.3
0%
Низкий
почти 11 лет назад

Уязвимостей на страницу


Поделиться