Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field parameter in a popup action to an admin change form page, as demonstrated by a /admin/auth/user/?pop=1&t=password URI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Django 权限许可和访问控制漏洞
Vulnerability Description
Django是Django软件基金会的一套基于Python语言的开源Web应用框架。该框架包括面向对象的映射器、视图系统、模板系统等。 Django的后台管理接口 (contrib.admin) 中存在安全漏洞,该漏洞源于程序没有检查模型间的关系是否由字段表示。远程攻击者可借助管理员更改表单页面执行popup操作中的‘to_field parameter’参数,利用该漏洞获取敏感信息。以下版本受到影响:Django 1.4.13及之前版本,1.5.9之前1.5.x版本,1.6.6之前1.6.x版本,rel
CVSS Information
N/A
Vulnerability Type
N/A