Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"

Количество 775

Количество 775

ubuntu логотип

CVE-2014-0480

больше 11 лет назад

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2014-0480

больше 11 лет назад

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-0480

больше 11 лет назад

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2014-0480

больше 11 лет назад

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2014-0474

почти 12 лет назад

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

CVSS2: 10
EPSS: Низкий
redhat логотип

CVE-2014-0474

почти 12 лет назад

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-0474

почти 12 лет назад

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2014-0474

почти 12 лет назад

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressFie ...

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2014-0473

почти 12 лет назад

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2014-0473

почти 12 лет назад

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-0473

почти 12 лет назад

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-0473

почти 12 лет назад

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6 ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-0472

почти 12 лет назад

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2014-0472

почти 12 лет назад

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-0472

почти 12 лет назад

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

CVSS2: 5.1
EPSS: Низкий
debian логотип

CVE-2014-0472

почти 12 лет назад

The django.core.urlresolvers.reverse function in Django before 1.4.11, ...

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2013-6044

больше 12 лет назад

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities into Django applications that use this function, as demonstrated by "the login view in django.contrib.auth.views" and the javascript: scheme.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2013-6044

больше 12 лет назад

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities into Django applications that use this function, as demonstrated by "the login view in django.contrib.auth.views" and the javascript: scheme.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-6044

больше 12 лет назад

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities into Django applications that use this function, as demonstrated by "the login view in django.contrib.auth.views" and the javascript: scheme.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-6044

больше 12 лет назад

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6 ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-0480

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.

CVSS2: 5.8
1%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-0480

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0480

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.

CVSS2: 5.8
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0480

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x ...

CVSS2: 5.8
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-0474

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

CVSS2: 10
4%
Низкий
почти 12 лет назад
redhat логотип
CVE-2014-0474

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

CVSS2: 4.3
4%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-0474

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

CVSS2: 10
4%
Низкий
почти 12 лет назад
debian логотип
CVE-2014-0474

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressFie ...

CVSS2: 10
4%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-0473

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.

CVSS2: 5
0%
Низкий
почти 12 лет назад
redhat логотип
CVE-2014-0473

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.

CVSS2: 4.3
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-0473

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.

CVSS2: 5
0%
Низкий
почти 12 лет назад
debian логотип
CVE-2014-0473

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6 ...

CVSS2: 5
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-0472

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

CVSS2: 5.1
7%
Низкий
почти 12 лет назад
redhat логотип
CVE-2014-0472

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

CVSS2: 4.3
7%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-0472

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

CVSS2: 5.1
7%
Низкий
почти 12 лет назад
debian логотип
CVE-2014-0472

The django.core.urlresolvers.reverse function in Django before 1.4.11, ...

CVSS2: 5.1
7%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-6044

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities into Django applications that use this function, as demonstrated by "the login view in django.contrib.auth.views" and the javascript: scheme.

CVSS2: 4.3
4%
Низкий
больше 12 лет назад
redhat логотип
CVE-2013-6044

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities into Django applications that use this function, as demonstrated by "the login view in django.contrib.auth.views" and the javascript: scheme.

CVSS2: 4.3
4%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-6044

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities into Django applications that use this function, as demonstrated by "the login view in django.contrib.auth.views" and the javascript: scheme.

CVSS2: 4.3
4%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-6044

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6 ...

CVSS2: 4.3
4%
Низкий
больше 12 лет назад

Уязвимостей на страницу