CVE-2015-5143
- EPSS 7.27%
- Veröffentlicht 14.07.2015 17:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multiple requests with unique session keys.
- EPSS 1.75%
- Veröffentlicht 02.06.2015 14:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.
CVE-2015-2317
- EPSS 4.99%
- Veröffentlicht 25.03.2015 14:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a con...
- EPSS 4.96%
- Veröffentlicht 25.03.2015 14:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the ...
CVE-2015-2241
- EPSS 2.07%
- Veröffentlicht 12.03.2015 14:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as d...
- EPSS 2.71%
- Veröffentlicht 16.01.2015 16:59:21
- Zuletzt bearbeitet 06.05.2026 22:30:45
ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.
- EPSS 4.37%
- Veröffentlicht 16.01.2015 16:59:20
- Zuletzt bearbeitet 06.05.2026 22:30:45
The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.
CVE-2015-0220
- EPSS 3.05%
- Veröffentlicht 16.01.2015 16:59:19
- Zuletzt bearbeitet 06.05.2026 22:30:45
The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL...
- EPSS 6.78%
- Veröffentlicht 16.01.2015 16:59:18
- Zuletzt bearbeitet 06.05.2026 22:30:45
Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.
CVE-2014-0480
- EPSS 2.3%
- Veröffentlicht 26.08.2014 14:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slas...