Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"

Количество 751

Количество 751

ubuntu логотип

CVE-2013-4249

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before 1.6 beta 2 allows remote attackers to inject arbitrary web script or HTML via a URLField.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-4249

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before 1.6 beta 2 allows remote attackers to inject arbitrary web script or HTML via a URLField.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-4249

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget wi ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-1443

больше 12 лет назад

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2013-1443

больше 12 лет назад

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-1443

больше 12 лет назад

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2013-1443

больше 12 лет назад

The authentication framework (django.contrib.auth) in Django 1.4.x bef ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2013-0306

почти 13 лет назад

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2013-0306

почти 13 лет назад

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-0306

почти 13 лет назад

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2013-0306

почти 13 лет назад

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2013-0305

почти 13 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2013-0305

почти 13 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2013-0305

почти 13 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2013-0305

почти 13 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x befo ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-4520

около 13 лет назад

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 6.4
EPSS: Низкий
redhat логотип

CVE-2012-4520

больше 13 лет назад

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-4520

около 13 лет назад

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2012-4520

около 13 лет назад

The django.http.HttpRequest.get_host function in Django 1.3.x before 1 ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2012-3444

больше 13 лет назад

The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2013-4249

Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before 1.6 beta 2 allows remote attackers to inject arbitrary web script or HTML via a URLField.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4249

Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before 1.6 beta 2 allows remote attackers to inject arbitrary web script or HTML via a URLField.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-4249

Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget wi ...

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-1443

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.

CVSS2: 5
1%
Низкий
больше 12 лет назад
redhat логотип
CVE-2013-1443

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-1443

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.

CVSS2: 5
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-1443

The authentication framework (django.contrib.auth) in Django 1.4.x bef ...

CVSS2: 5
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-0306

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

CVSS2: 5
0%
Низкий
почти 13 лет назад
redhat логотип
CVE-2013-0306

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

CVSS2: 5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0306

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

CVSS2: 5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-0306

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and ...

CVSS2: 5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-0305

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS2: 4
0%
Низкий
почти 13 лет назад
redhat логотип
CVE-2013-0305

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS2: 4
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0305

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS2: 4
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-0305

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x befo ...

CVSS2: 4
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-4520

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 6.4
4%
Низкий
около 13 лет назад
redhat логотип
CVE-2012-4520

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 4.3
4%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-4520

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 6.4
4%
Низкий
около 13 лет назад
debian логотип
CVE-2012-4520

The django.http.HttpRequest.get_host function in Django 1.3.x before 1 ...

CVSS2: 6.4
4%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2012-3444

The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.

CVSS2: 5
1%
Низкий
больше 13 лет назад

Уязвимостей на страницу