Djangoproject

Django

123 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 5.88%
  • Published 23.04.2014 15:55:02
  • Last modified 12.04.2025 10:46:40

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URL...

  • EPSS 4.12%
  • Published 04.10.2013 17:55:10
  • Last modified 11.04.2025 00:51:21

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities...

Exploit
  • EPSS 0.28%
  • Published 04.10.2013 17:55:09
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before 1.6 beta 2 allows remote attackers to inject arbitrary web script or HTML via a URLField.

  • EPSS 1.17%
  • Published 23.09.2013 20:55:07
  • Last modified 11.04.2025 00:51:21

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.

  • EPSS 0.98%
  • Published 16.09.2013 19:14:39
  • Last modified 11.04.2025 00:51:21

Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbitrary files via a file path in the ALLOWED_INCLUDE_ROOTS setting followed by a .. (dot dot) in a ssi t...

  • EPSS 0.21%
  • Published 02.05.2013 14:55:05
  • Last modified 11.04.2025 00:51:21

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history in...

  • EPSS 0.56%
  • Published 02.05.2013 14:55:05
  • Last modified 11.04.2025 00:51:21

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors ...

  • EPSS 4.44%
  • Published 18.11.2012 23:55:01
  • Last modified 11.04.2025 00:51:21

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

  • EPSS 1.38%
  • Published 31.07.2012 17:55:04
  • Last modified 11.04.2025 00:51:21

The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image validation, which allows remote attackers to cause a denial of service (memory consumption) by uploadin...

  • EPSS 1.19%
  • Published 31.07.2012 17:55:04
  • Last modified 11.04.2025 00:51:21

The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (proces...