6.4
CVSSv2

CVE-2012-4520

Published: 18/11/2012 Updated: 04/05/2013
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The django.http.HttpRequest.get_host function in Django 1.3.x prior to 1.3.4 and 1.4.x prior to 1.4.2 allows remote malicious users to generate and display arbitrary URLs via crafted username and password Host header values.

Vulnerable Product Search on Vulmon Subscribe to Product

djangoproject django 1.3.2

djangoproject django 1.3.3

djangoproject django 1.3

djangoproject django 1.3.1

djangoproject django 1.4

djangoproject django 1.4.1

Vendor Advisories

Debian Bug report logs - #701186 python-django: CVE-2013-0305 CVE-2013-0306 Package: python-django; Maintainer for python-django is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Source for python-django is src:python-django (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg& ...
Debian Bug report logs - #691145 python-django: CVE-2012-4520 Package: python-django; Maintainer for python-django is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Source for python-django is src:python-django (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon ...
Several security issues were fixed in Django ...
Django could be made to expose sensitive information over the network ...