5
CVSSv2

CVE-2010-4535

Published: 10/01/2011 Updated: 20/01/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The password reset functionality in django.contrib.auth in Django prior to 1.1.3, 1.2.x prior to 1.2.4, and 1.3.x prior to 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote malicious users to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer.

Vulnerable Product Search on Vulmon Subscribe to Product

djangoproject django 1.0

djangoproject django 1.0.1

djangoproject django 1.0.2

djangoproject django 0.95.1

djangoproject django 0.96

djangoproject django 1.1

djangoproject django

djangoproject django 0.91

djangoproject django 0.95

djangoproject django 1.1.0

djangoproject django 1.2.3

djangoproject django 1.2

djangoproject django 1.2.1

djangoproject django 1.2.2

djangoproject django 1.3

Vendor Advisories

An attacker could send crafted input to Django and cause it to utilize too many resources ...