Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"
Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

4.25.05.15.22023202420252026202720282029

Недавние уязвимости Django

Количество 679

nvd логотип

CVE-2013-0305

больше 12 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2013-0305

больше 12 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x befo ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2013-0305

больше 12 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2013-0306

больше 12 лет назад

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2013-0306

больше 12 лет назад

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2013-0305

больше 12 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-4520

почти 13 лет назад

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2012-4520

почти 13 лет назад

The django.http.HttpRequest.get_host function in Django 1.3.x before 1 ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2012-4520

почти 13 лет назад

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 6.4
EPSS: Низкий
redhat логотип

CVE-2012-4520

почти 13 лет назад

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2013-0305

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS2: 4
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-0305

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x befo ...

CVSS2: 4
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-0305

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS2: 4
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-0306

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

CVSS2: 5
1%
Низкий
больше 12 лет назад
redhat логотип
CVE-2013-0306

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

CVSS2: 5
1%
Низкий
больше 12 лет назад
redhat логотип
CVE-2013-0305

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS2: 4
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-4520

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 6.4
4%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-4520

The django.http.HttpRequest.get_host function in Django 1.3.x before 1 ...

CVSS2: 6.4
4%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-4520

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 6.4
4%
Низкий
почти 13 лет назад
redhat логотип
CVE-2012-4520

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 4.3
4%
Низкий
почти 13 лет назад

Уязвимостей на страницу


Поделиться