VDB

DEBIAN-CVE-2012-4520

DEBIAN-CVE-2012-4520 PUBLISHED

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

Affected Products

VendorProductVersions
Debian:14python-django0, 0, 0
Debian:13python-django0, 0, 0
Debian:11python-django0, 0, 0
Debian:12python-django0, 0, 0

Timeline

  • Nov 18, 2012 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›