CVE-2012-4520
EUVD-2012-000618.11.2012, 23:55
The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| djangoproject | django | 1.3 |
| djangoproject | django | 1.3:alpha1 |
| djangoproject | django | 1.3:beta1 |
| djangoproject | django | 1.3.1 |
| djangoproject | django | 1.3.2 |
| djangoproject | django | 1.3.3 |
| djangoproject | django | 1.4 |
| djangoproject | django | 1.4.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References