[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3230-1 django-markupfield -- django-markupfield

ID: oval:org.secpod.oval:def:602052Date: (C)2015-04-22   (M)2021-06-02
Class: PATCHFamily: unix




James P. Turk discovered that the ReST renderer in django-markupfield, a custom Django field for easy use of markup in text fields, didn"t disable the ..raw directive, allowing remote attackers to include arbitrary files.

Platform:
Debian 7.0
Product:
python-django-markupfield
Reference:
DSA-3230-1
CVE-2015-0846
CVE    1
CVE-2015-0846
CPE    2
cpe:/a:djangoproject:python-django-markupfield
cpe:/o:debian:debian_linux:7.x

© SecPod Technologies