CVE-2014-0472
- EPSS 5.88%
- Veröffentlicht 23.04.2014 15:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URL...
CVE-2013-6044
- EPSS 4.12%
- Veröffentlicht 04.10.2013 17:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities...
CVE-2013-4249
- EPSS 0.28%
- Veröffentlicht 04.10.2013 17:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before 1.6 beta 2 allows remote attackers to inject arbitrary web script or HTML via a URLField.
- EPSS 1.17%
- Veröffentlicht 23.09.2013 20:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.
- EPSS 0.98%
- Veröffentlicht 16.09.2013 19:14:39
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbitrary files via a file path in the ALLOWED_INCLUDE_ROOTS setting followed by a .. (dot dot) in a ssi t...
- EPSS 0.21%
- Veröffentlicht 02.05.2013 14:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history in...
- EPSS 0.56%
- Veröffentlicht 02.05.2013 14:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors ...
CVE-2012-4520
- EPSS 4.44%
- Veröffentlicht 18.11.2012 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.
- EPSS 1.38%
- Veröffentlicht 31.07.2012 17:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image validation, which allows remote attackers to cause a denial of service (memory consumption) by uploadin...
- EPSS 1.19%
- Veröffentlicht 31.07.2012 17:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (proces...