Sploitus

CVE-2014-0472

1 known exploit for CVE-2014-0472

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

Affected products
Django, Ubuntu
Djangoproject Django
≤ 1.4.10, 1.4, 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, 1.4.8, 1.4.9
Fix
Available
CVSS 2.0
5.1 MEDIUM
EPSS
5.7% (92th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2014-04-23
CVE-2014-0472 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2014-0472

Proof-of-concept code and exploit modules indexed by Sploitus