Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"

Количество 673

Количество 673

nvd логотип

CVE-2015-3982

около 10 лет назад

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-3982

около 10 лет назад

The session.flush function in the cached_db backend in Django 1.8.x be ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-2317

около 10 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-2317

больше 10 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2015-2317

около 10 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-2317

около 10 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1. ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-2316

около 10 лет назад

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2015-2316

больше 10 лет назад

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-2316

около 10 лет назад

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-2316

около 10 лет назад

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7. ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-2241

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-2241

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-2241

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-2241

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the contents function in a ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-0222

больше 10 лет назад

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2015-0222

больше 10 лет назад

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-0222

больше 10 лет назад

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-0222

больше 10 лет назад

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x befor ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-0221

больше 10 лет назад

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2015-0221

больше 10 лет назад

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2015-3982

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.

CVSS2: 5
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-3982

The session.flush function in the cached_db backend in Django 1.8.x be ...

CVSS2: 5
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-2317

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

CVSS2: 4.3
3%
Низкий
около 10 лет назад
redhat логотип
CVE-2015-2317

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

CVSS2: 2.6
3%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-2317

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

CVSS2: 4.3
3%
Низкий
около 10 лет назад
debian логотип
CVE-2015-2317

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1. ...

CVSS2: 4.3
3%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-2316

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 5
2%
Низкий
около 10 лет назад
redhat логотип
CVE-2015-2316

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 4.3
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-2316

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 5
2%
Низкий
около 10 лет назад
debian логотип
CVE-2015-2316

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7. ...

CVSS2: 5
2%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-2241

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
redhat логотип
CVE-2015-2241

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-2241

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-2241

Cross-site scripting (XSS) vulnerability in the contents function in a ...

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-0222

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 5
5%
Низкий
больше 10 лет назад
redhat логотип
CVE-2015-0222

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 4.3
5%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-0222

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 5
5%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-0222

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x befor ...

CVSS2: 5
5%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-0221

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 5
9%
Низкий
больше 10 лет назад
redhat логотип
CVE-2015-0221

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 4.3
9%
Низкий
больше 10 лет назад

Уязвимостей на страницу