Vulnerabilities
Vulnerable Software
Djangoproject:  >> Django  >> 1.8  Security Vulnerabilities
Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP response splitting attacks via a newline character in an (1) email message to the EmailValidator, a (2) URL to the URLValidator, or unspecified vectors to the (3) validate_ipv4_address or (4) validate_slug validator.
CVSS Score
4.3
EPSS Score
0.015
Published
2015-07-14
Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.
CVSS Score
4.3
EPSS Score
0.003
Published
2015-03-12


Contact Us

Shodan ® - All rights reserved