Skip to main content

Vendor/product archive

django_project / django CVEs

Beta · best-effort

6 CVEs tagged to django_project / django0 Critical, 1 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2009-2659

Published Aug 4, 2009

The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to co…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2302

Published May 23, 2008

Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5828

Published Nov 5, 2007

Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5712

Published Oct 30, 2007

The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component ar…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0404

Published Jan 23, 2007

bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0405

Published Jan 23, 2007

The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1