Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"

Количество 751

Количество 751

debian логотип

CVE-2010-3082

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in Django 1.2.x before 1.2.2 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2009-3695

больше 16 лет назад

Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) EmailField (email address) or (2) URLField (URL) that triggers a large amount of backtracking in a regular expression.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-3695

больше 16 лет назад

Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) EmailField (email address) or (2) URLField (URL) that triggers a large amount of backtracking in a regular expression.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-3695

больше 16 лет назад

Algorithmic complexity vulnerability in the forms library in Django 1. ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-2659

больше 16 лет назад

The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2009-2659

больше 16 лет назад

The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL.

EPSS: Низкий
nvd логотип

CVE-2009-2659

больше 16 лет назад

The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-2659

больше 16 лет назад

The Admin media handler in core/servers/basehttp.py in Django 1.0 and ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-3909

больше 17 лет назад

The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2008-3909

больше 17 лет назад

The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2008-3909

больше 17 лет назад

The administration application in Django 0.91, 0.95, and 0.96 stores u ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2008-2302

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2008-2302

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.

EPSS: Низкий
nvd логотип

CVE-2008-2302

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-2302

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in the login form in the admi ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-5828

около 18 лет назад

Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2007-5828

больше 18 лет назад

Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module

EPSS: Низкий
nvd логотип

CVE-2007-5828

около 18 лет назад

Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-5828

около 18 лет назад

Cross-site request forgery (CSRF) vulnerability in the admin panel in ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-5712

больше 18 лет назад

The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers.

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2010-3082

Cross-site scripting (XSS) vulnerability in Django 1.2.x before 1.2.2 ...

CVSS2: 4.3
0%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-3695

Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) EmailField (email address) or (2) URLField (URL) that triggers a large amount of backtracking in a regular expression.

CVSS2: 5
6%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-3695

Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) EmailField (email address) or (2) URLField (URL) that triggers a large amount of backtracking in a regular expression.

CVSS2: 5
6%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3695

Algorithmic complexity vulnerability in the forms library in Django 1. ...

CVSS2: 5
6%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-2659

The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL.

CVSS2: 5
1%
Низкий
больше 16 лет назад
redhat логотип
CVE-2009-2659

The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL.

1%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-2659

The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL.

CVSS2: 5
1%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-2659

The Admin media handler in core/servers/basehttp.py in Django 1.0 and ...

CVSS2: 5
1%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2008-3909

The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.

CVSS2: 5.8
0%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-3909

The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.

CVSS2: 5.8
0%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-3909

The administration application in Django 0.91, 0.95, and 0.96 stores u ...

CVSS2: 5.8
0%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-2302

Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.

CVSS2: 4.3
0%
Низкий
больше 17 лет назад
redhat логотип
CVE-2008-2302

Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.

0%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-2302

Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.

CVSS2: 4.3
0%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-2302

Cross-site scripting (XSS) vulnerability in the login form in the admi ...

CVSS2: 4.3
0%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2007-5828

Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module

CVSS2: 6.8
0%
Низкий
около 18 лет назад
redhat логотип
CVE-2007-5828

Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module

0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-5828

Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module

CVSS2: 6.8
0%
Низкий
около 18 лет назад
debian логотип
CVE-2007-5828

Cross-site request forgery (CSRF) vulnerability in the admin panel in ...

CVSS2: 6.8
0%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-5712

The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers.

CVSS2: 2.6
2%
Низкий
больше 18 лет назад

Уязвимостей на страницу