Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"

Количество 751

Количество 751

ubuntu логотип

CVE-2014-0474

почти 12 лет назад

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

CVSS2: 10
EPSS: Низкий
redhat логотип

CVE-2014-0474

почти 12 лет назад

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-0474

почти 12 лет назад

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2014-0474

почти 12 лет назад

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressFie ...

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2014-0473

почти 12 лет назад

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2014-0473

почти 12 лет назад

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-0473

почти 12 лет назад

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-0473

почти 12 лет назад

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6 ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-0472

почти 12 лет назад

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2014-0472

почти 12 лет назад

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-0472

почти 12 лет назад

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

CVSS2: 5.1
EPSS: Низкий
debian логотип

CVE-2014-0472

почти 12 лет назад

The django.core.urlresolvers.reverse function in Django before 1.4.11, ...

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2013-6044

больше 12 лет назад

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities into Django applications that use this function, as demonstrated by "the login view in django.contrib.auth.views" and the javascript: scheme.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2013-6044

больше 12 лет назад

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities into Django applications that use this function, as demonstrated by "the login view in django.contrib.auth.views" and the javascript: scheme.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-6044

больше 12 лет назад

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities into Django applications that use this function, as demonstrated by "the login view in django.contrib.auth.views" and the javascript: scheme.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-6044

больше 12 лет назад

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-4315

больше 12 лет назад

Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbitrary files via a file path in the ALLOWED_INCLUDE_ROOTS setting followed by a .. (dot dot) in a ssi template tag.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2013-4315

больше 12 лет назад

Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbitrary files via a file path in the ALLOWED_INCLUDE_ROOTS setting followed by a .. (dot dot) in a ssi template tag.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-4315

больше 12 лет назад

Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbitrary files via a file path in the ALLOWED_INCLUDE_ROOTS setting followed by a .. (dot dot) in a ssi template tag.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2013-4315

больше 12 лет назад

Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-0474

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

CVSS2: 10
4%
Низкий
почти 12 лет назад
redhat логотип
CVE-2014-0474

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

CVSS2: 4.3
4%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-0474

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

CVSS2: 10
4%
Низкий
почти 12 лет назад
debian логотип
CVE-2014-0474

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressFie ...

CVSS2: 10
4%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-0473

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.

CVSS2: 5
0%
Низкий
почти 12 лет назад
redhat логотип
CVE-2014-0473

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.

CVSS2: 4.3
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-0473

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.

CVSS2: 5
0%
Низкий
почти 12 лет назад
debian логотип
CVE-2014-0473

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6 ...

CVSS2: 5
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-0472

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

CVSS2: 5.1
7%
Низкий
почти 12 лет назад
redhat логотип
CVE-2014-0472

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

CVSS2: 4.3
7%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-0472

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

CVSS2: 5.1
7%
Низкий
почти 12 лет назад
debian логотип
CVE-2014-0472

The django.core.urlresolvers.reverse function in Django before 1.4.11, ...

CVSS2: 5.1
7%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-6044

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities into Django applications that use this function, as demonstrated by "the login view in django.contrib.auth.views" and the javascript: scheme.

CVSS2: 4.3
4%
Низкий
больше 12 лет назад
redhat логотип
CVE-2013-6044

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities into Django applications that use this function, as demonstrated by "the login view in django.contrib.auth.views" and the javascript: scheme.

CVSS2: 4.3
4%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-6044

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities into Django applications that use this function, as demonstrated by "the login view in django.contrib.auth.views" and the javascript: scheme.

CVSS2: 4.3
4%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-6044

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6 ...

CVSS2: 4.3
4%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-4315

Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbitrary files via a file path in the ALLOWED_INCLUDE_ROOTS setting followed by a .. (dot dot) in a ssi template tag.

CVSS2: 5
1%
Низкий
больше 12 лет назад
redhat логотип
CVE-2013-4315

Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbitrary files via a file path in the ALLOWED_INCLUDE_ROOTS setting followed by a .. (dot dot) in a ssi template tag.

CVSS2: 2.1
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4315

Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbitrary files via a file path in the ALLOWED_INCLUDE_ROOTS setting followed by a .. (dot dot) in a ssi template tag.

CVSS2: 5
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-4315

Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x ...

CVSS2: 5
1%
Низкий
больше 12 лет назад

Уязвимостей на страницу