Логотип exploitDog
bind:CVE-2015-0220
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-0220

Количество 5

Количество 5

ubuntu логотип

CVE-2015-0220

больше 10 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-0220

больше 10 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-0220

больше 10 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-0220

больше 10 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6 ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-gv98-g628-m9x5

около 3 лет назад

Django Cross-site Scripting Vulnerability

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-0220

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
2%
Низкий
больше 10 лет назад
redhat логотип
CVE-2015-0220

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-0220

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
2%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-0220

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6 ...

CVSS2: 4.3
2%
Низкий
больше 10 лет назад
github логотип
GHSA-gv98-g628-m9x5

Django Cross-site Scripting Vulnerability

CVSS3: 6.1
2%
Низкий
около 3 лет назад

Уязвимостей на страницу