CVE-2014-0483
- EPSS 0.43%
- Veröffentlicht 26.08.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated use...
CVE-2014-3730
- EPSS 0.99%
- Veröffentlicht 16.05.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as de...
CVE-2014-1418
- EPSS 0.51%
- Veröffentlicht 16.05.2014 15:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the ca...
- EPSS 0.37%
- Veröffentlicht 23.04.2014 15:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie...
- EPSS 5.94%
- Veröffentlicht 23.04.2014 15:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote att...
CVE-2014-0472
- EPSS 5.88%
- Veröffentlicht 23.04.2014 15:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URL...
CVE-2013-6044
- EPSS 4.12%
- Veröffentlicht 04.10.2013 17:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities...
CVE-2013-4249
- EPSS 0.31%
- Veröffentlicht 04.10.2013 17:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before 1.6 beta 2 allows remote attackers to inject arbitrary web script or HTML via a URLField.
- EPSS 1.04%
- Veröffentlicht 23.09.2013 20:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.
- EPSS 0.98%
- Veröffentlicht 16.09.2013 19:14:39
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbitrary files via a file path in the ALLOWED_INCLUDE_ROOTS setting followed by a .. (dot dot) in a ssi t...