Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-3730
Description:The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."
Test IDs: 1.3.6.1.4.1.25623.1.0.702934  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-3730
BugTraq ID: 67410
http://www.securityfocus.com/bid/67410
Debian Security Information: DSA-2934 (Google Search)
http://www.debian.org/security/2014/dsa-2934
http://www.openwall.com/lists/oss-security/2014/05/14/10
http://www.openwall.com/lists/oss-security/2014/05/15/3
http://secunia.com/advisories/61281
SuSE Security Announcement: openSUSE-SU-2014:1132 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-09/msg00023.html
http://ubuntu.com/usn/usn-2212-1




© 1998-2025 E-Soft Inc. All rights reserved.