Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-9013
Description:Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.
Test IDs: 1.3.6.1.4.1.25623.1.0.703835  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-9013
BugTraq ID: 94069
http://www.securityfocus.com/bid/94069
Debian Security Information: DSA-3835 (Google Search)
http://www.debian.org/security/2017/dsa-3835
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OG5ROMUPS6C7BXELD3TAUUH7OBYV56WQ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QXDKJYHN74BWY3P7AR2UZDVJREQMRE6S/
http://www.securitytracker.com/id/1037159
http://www.ubuntu.com/usn/USN-3115-1




© 1998-2025 E-Soft Inc. All rights reserved.