Количество 4
Количество 4

CVE-2011-4138
The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 originally tests a URL's validity through a HEAD request, but then uses a GET request for the new target URL in the case of a redirect, which might allow remote attackers to trigger arbitrary GET requests with an unintended source IP address via a crafted Location header.

CVE-2011-4138
The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 originally tests a URL's validity through a HEAD request, but then uses a GET request for the new target URL in the case of a redirect, which might allow remote attackers to trigger arbitrary GET requests with an unintended source IP address via a crafted Location header.
CVE-2011-4138
The verify_exists functionality in the URLField implementation in Djan ...
GHSA-wxg3-mfph-qg9w
Django Might Allow CSRF Requests via URL Verification
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2011-4138 The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 originally tests a URL's validity through a HEAD request, but then uses a GET request for the new target URL in the case of a redirect, which might allow remote attackers to trigger arbitrary GET requests with an unintended source IP address via a crafted Location header. | CVSS2: 5 | 1% Низкий | больше 13 лет назад |
![]() | CVE-2011-4138 The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 originally tests a URL's validity through a HEAD request, but then uses a GET request for the new target URL in the case of a redirect, which might allow remote attackers to trigger arbitrary GET requests with an unintended source IP address via a crafted Location header. | CVSS2: 5 | 1% Низкий | больше 13 лет назад |
CVE-2011-4138 The verify_exists functionality in the URLField implementation in Djan ... | CVSS2: 5 | 1% Низкий | больше 13 лет назад | |
GHSA-wxg3-mfph-qg9w Django Might Allow CSRF Requests via URL Verification | CVSS3: 7.5 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу