Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown

CVE-2014-3730

Disclosure Date: May 16, 2014 (last updated October 05, 2023)
The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."
0
Attacker Value
Unknown

CVE-2014-1418

Disclosure Date: May 16, 2014 (last updated October 05, 2023)
Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.
0
Attacker Value
Unknown

CVE-2014-0474

Disclosure Date: April 23, 2014 (last updated October 05, 2023)
The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."
0
Attacker Value
Unknown

CVE-2014-0472

Disclosure Date: April 23, 2014 (last updated October 05, 2023)
The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."
0
Attacker Value
Unknown

CVE-2014-0473

Disclosure Date: April 23, 2014 (last updated October 05, 2023)
The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.
0
Attacker Value
Unknown

CVE-2013-1468

Disclosure Date: March 14, 2013 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor plugin in Piwigo before 2.4.7 allows remote attackers to hijack the authentication of administrators for requests that create arbitrary PHP files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-1469

Disclosure Date: March 13, 2013 (last updated October 05, 2023)
Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the dl parameter.
0
Attacker Value
Unknown

CVE-2012-1395

Disclosure Date: March 07, 2012 (last updated October 04, 2023)
Unspecified vulnerability in the GO TwiWidget (com.gau.go.launcherex.gowidget.twitterwidget) application 1.7 and 2.1 for Android has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2011-0020

Disclosure Date: January 24, 2011 (last updated October 04, 2023)
Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.
0
Attacker Value
Unknown

CVE-2010-1707

Disclosure Date: May 04, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Piwigo 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) login and (2) mail_address parameters.
0