VendorsDjango Projectdjango1.3.3
Vulnerabilities

Django Project Django 1.3.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2012-4520
The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.
Published 2012-11-18 · Modified
6.4EPSS 0.037
CVE-2013-0306
The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.
Published 2013-05-02 · Modified
5.0EPSS 0.026
CVE-2013-0305
The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.
Published 2013-05-02 · Modified
4.0EPSS 0.018