CVE-2015-2241
- EPSS 0.26%
- Veröffentlicht 12.03.2015 14:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as d...
- EPSS 5.84%
- Veröffentlicht 16.01.2015 16:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.
- EPSS 9.15%
- Veröffentlicht 16.01.2015 16:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.
CVE-2015-0220
- EPSS 2.55%
- Veröffentlicht 16.01.2015 16:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL...
- EPSS 4.84%
- Veröffentlicht 16.01.2015 16:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.
CVE-2014-0480
- EPSS 0.56%
- Veröffentlicht 26.08.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slas...
CVE-2014-0481
- EPSS 1.12%
- Veröffentlicht 26.08.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is up...
- EPSS 0.71%
- Veröffentlicht 26.08.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticat...
CVE-2014-0483
- EPSS 0.43%
- Veröffentlicht 26.08.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated use...
CVE-2014-3730
- EPSS 0.99%
- Veröffentlicht 16.05.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as de...