Django 'HttpRequest.get_host()' Information Disclosure Vulnerability
BID:56146
Info
Django 'HttpRequest.get_host()' Information Disclosure Vulnerability
| Bugtraq ID: | 56146 |
| Class: | Design Error |
| CVE: |
CVE-2012-4520 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 19 2012 12:00AM |
| Updated: | Apr 16 2015 05:51PM |
| Credit: | James Kettle |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Django Django 1.3.1 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
Django 'HttpRequest.get_host()' Information Disclosure Vulnerability
Django is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
Django is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
Exploit / POC
Django 'HttpRequest.get_host()' Information Disclosure Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Django 'HttpRequest.get_host()' Information Disclosure Vulnerability
Solution:
Updates are available; please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
Mandriva Linux Mandrake 2011 x86_64
Mandriva Linux Mandrake 2011
MandrakeSoft Enterprise Server 5
Solution:
Updates are available; please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva python-django-1.3.5-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011 x86_64
-
Mandriva python-django-1.3.5-0.1-mdv2011.0.noarch.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva python-django-1.3.5-0.1-mdv2011.0.noarch.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva python-django-1.3.5-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
References
Django 'HttpRequest.get_host()' Information Disclosure Vulnerability
References:
References:
- Django Homepage (Django)