[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

USN-1066-1 -- python-django vulnerabilities

ID: oval:org.secpod.oval:def:700236Date: (C)2011-02-21   (M)2021-09-12
Class: PATCHFamily: unix




It was discovered that Django did not properly validate HTTP requests that contain an X-Requested-With header. An attacker could exploit this vulnerability to perform cross-site request forgery attacks. It was discovered that Django did not properly sanitize its input when performing file uploads, resulting in cross-site scripting vulnerabilities. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain

Platform:
Ubuntu 10.10
Ubuntu 9.10
Ubuntu 10.04
Product:
python-django
Reference:
USN-1066-1
CVE-2011-0696
CVE-2011-0697
CVE    2
CVE-2011-0697
CVE-2011-0696
CPE    3
cpe:/o:ubuntu:ubuntu_linux:10.04
cpe:/o:ubuntu:ubuntu_linux:9.10
cpe:/o:ubuntu:ubuntu_linux:10.10

© SecPod Technologies