4.3
CVSSv2

CVE-2011-0697

Published: 14/02/2011 Updated: 11/03/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Django 1.1.x prior to 1.1.4 and 1.2.x prior to 1.2.5 might allow remote malicious users to inject arbitrary web script or HTML via a filename associated with a file upload.

Vulnerable Product Search on Vulmon Subscribe to Product

djangoproject django 1.1

djangoproject django 1.1.3

djangoproject django 1.1.0

djangoproject django 1.1.2

djangoproject django 1.2.1

djangoproject django 1.2.2

djangoproject django 1.2.3

djangoproject django 1.2.4

djangoproject django 1.2

Vendor Advisories

Attackers could use Django to perform web-based attacks ...
Several vulnerabilities were discovered in the Django web development framework: CVE-2011-0696 For several reasons the internal CSRF protection was not used to validate AJAX requests in the past However, it was discovered that this exception can be exploited with a combination of browser plugins and redirects and thus is not suffi ...