CVE-2014-0472
The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."
- Djangoproject Django
- ≤ 1.4.10, 1.4, 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, 1.4.8, 1.4.9
- Fix
- Available
- CVSS 2.0
- 5.1 MEDIUM
- EPSS
- 5.7% (92th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2014-04-23
CVE-2014-0472 at NVD
1 known exploit for CVE-2014-0472
Proof-of-concept code and exploit modules indexed by Sploitus