CVE-2012-4520

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:djangoproject:django:1.3:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:1.3:alpha1:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:1.3:beta1:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:1.3.3:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:djangoproject:django:1.4:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:1.4.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2012-11-18 23:55

Updated : 2024-02-04 18:16


NVD link : CVE-2012-4520

Mitre link : CVE-2012-4520

CVE.ORG link : CVE-2012-4520


JSON object : View

Products Affected

djangoproject

  • django
CWE
CWE-20

Improper Input Validation