Djangoproject

Django

161 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 7.27%
  • Veröffentlicht 14.07.2015 17:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multiple requests with unique session keys.

  • EPSS 1.75%
  • Veröffentlicht 02.06.2015 14:59:10
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.

  • EPSS 4.99%
  • Veröffentlicht 25.03.2015 14:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a con...

  • EPSS 4.96%
  • Veröffentlicht 25.03.2015 14:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the ...

Exploit
  • EPSS 2.07%
  • Veröffentlicht 12.03.2015 14:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as d...

  • EPSS 2.71%
  • Veröffentlicht 16.01.2015 16:59:21
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

Exploit
  • EPSS 4.37%
  • Veröffentlicht 16.01.2015 16:59:20
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

Exploit
  • EPSS 3.05%
  • Veröffentlicht 16.01.2015 16:59:19
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL...

Exploit
  • EPSS 6.78%
  • Veröffentlicht 16.01.2015 16:59:18
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

  • EPSS 2.3%
  • Veröffentlicht 26.08.2014 14:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slas...