Lucene search

K
cveDebianCVE-2014-0472
HistoryApr 23, 2014 - 3:55 p.m.

CVE-2014-0472

2014-04-2315:55:02
CWE-94
debian
web.nvd.nist.gov
60
django
urlresolver
security vulnerability
remote execution
cve-2014-0472
nvd

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.022

Percentile

89.5%

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a “dotted Python path.”

Affected configurations

Nvd
Node
djangoprojectdjangoRange1.4.10
OR
djangoprojectdjangoMatch1.4
OR
djangoprojectdjangoMatch1.4.1
OR
djangoprojectdjangoMatch1.4.2
OR
djangoprojectdjangoMatch1.4.3
OR
djangoprojectdjangoMatch1.4.4
OR
djangoprojectdjangoMatch1.4.5
OR
djangoprojectdjangoMatch1.4.6
OR
djangoprojectdjangoMatch1.4.7
OR
djangoprojectdjangoMatch1.4.8
OR
djangoprojectdjangoMatch1.4.9
Node
djangoprojectdjangoMatch1.6
OR
djangoprojectdjangoMatch1.6.1
OR
djangoprojectdjangoMatch1.6.2
Node
djangoprojectdjangoMatch1.7alpha1
OR
djangoprojectdjangoMatch1.7alpha2
OR
djangoprojectdjangoMatch1.7beta1
Node
djangoprojectdjangoMatch1.5
OR
djangoprojectdjangoMatch1.5.1
OR
djangoprojectdjangoMatch1.5.2
OR
djangoprojectdjangoMatch1.5.3
OR
djangoprojectdjangoMatch1.5.4
OR
djangoprojectdjangoMatch1.5.5
Node
canonicalubuntu_linuxMatch10.04-lts
OR
canonicalubuntu_linuxMatch12.04-lts
OR
canonicalubuntu_linuxMatch12.10
OR
canonicalubuntu_linuxMatch13.10
OR
canonicalubuntu_linuxMatch14.04lts
VendorProductVersionCPE
djangoprojectdjango*cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
djangoprojectdjango1.4cpe:2.3:a:djangoproject:django:1.4:*:*:*:*:*:*:*
djangoprojectdjango1.4.1cpe:2.3:a:djangoproject:django:1.4.1:*:*:*:*:*:*:*
djangoprojectdjango1.4.2cpe:2.3:a:djangoproject:django:1.4.2:*:*:*:*:*:*:*
djangoprojectdjango1.4.3cpe:2.3:a:djangoproject:django:1.4.3:*:*:*:*:*:*:*
djangoprojectdjango1.4.4cpe:2.3:a:djangoproject:django:1.4.4:*:*:*:*:*:*:*
djangoprojectdjango1.4.5cpe:2.3:a:djangoproject:django:1.4.5:*:*:*:*:*:*:*
djangoprojectdjango1.4.6cpe:2.3:a:djangoproject:django:1.4.6:*:*:*:*:*:*:*
djangoprojectdjango1.4.7cpe:2.3:a:djangoproject:django:1.4.7:*:*:*:*:*:*:*
djangoprojectdjango1.4.8cpe:2.3:a:djangoproject:django:1.4.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 281

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.022

Percentile

89.5%