Djangoproject

Django

123 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.4%
  • Published 16.01.2015 16:59:19
  • Last modified 12.04.2025 10:46:40

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL...

Exploit
  • EPSS 3.72%
  • Published 16.01.2015 16:59:18
  • Last modified 12.04.2025 10:46:40

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

  • EPSS 0.56%
  • Published 26.08.2014 14:55:05
  • Last modified 12.04.2025 10:46:40

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slas...

  • EPSS 1.49%
  • Published 26.08.2014 14:55:05
  • Last modified 12.04.2025 10:46:40

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is up...

  • EPSS 0.71%
  • Published 26.08.2014 14:55:05
  • Last modified 12.04.2025 10:46:40

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticat...

Exploit
  • EPSS 0.43%
  • Published 26.08.2014 14:55:05
  • Last modified 12.04.2025 10:46:40

The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated use...

  • EPSS 0.99%
  • Published 16.05.2014 15:55:05
  • Last modified 12.04.2025 10:46:40

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as de...

  • EPSS 0.51%
  • Published 16.05.2014 15:55:04
  • Last modified 12.04.2025 10:46:40

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the ca...

  • EPSS 0.37%
  • Published 23.04.2014 15:55:03
  • Last modified 12.04.2025 10:46:40

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie...

  • EPSS 5.94%
  • Published 23.04.2014 15:55:03
  • Last modified 12.04.2025 10:46:40

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote att...