Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2015-2317

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

  • Published: Mar 25, 2015
  • Updated: Apr 13, 2023
  • CVE: CVE-2015-2317
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software From Fixed in
fedoraproject / fedora 22 22.x
debian / debian_linux 7.0 7.0.x
opensuse / opensuse 13.2 13.2.x
djangoproject / django 1.7.5 1.7.5.x
djangoproject / django 1.5 1.5.x
djangoproject / django 1.5.7 1.5.7.x
djangoproject / django 1.5.1 1.5.1.x
djangoproject / django 1.7.3 1.7.3.x
djangoproject / django 1.6-beta4 1.6-beta4.x
djangoproject / django - 1.4.19.x
djangoproject / django 1.6.7 1.6.7.x
djangoproject / django 1.7-rc2 1.7-rc2.x
djangoproject / django 1.7-beta1 1.7-beta1.x
djangoproject / django 1.6.5 1.6.5.x
djangoproject / django 1.6-beta2 1.6-beta2.x
djangoproject / django 1.5.3 1.5.3.x
djangoproject / django 1.7-beta3 1.7-beta3.x
djangoproject / django 1.5.4 1.5.4.x
djangoproject / django 1.5.12 1.5.12.x
djangoproject / django 1.6.8 1.6.8.x
djangoproject / django 1.5.10 1.5.10.x
djangoproject / django 1.5-beta 1.5-beta.x
djangoproject / django 1.6.6 1.6.6.x
djangoproject / django 1.5.5 1.5.5.x
djangoproject / django 1.7.2 1.7.2.x
djangoproject / django 1.7.4 1.7.4.x
djangoproject / django 1.6.10 1.6.10.x
djangoproject / django 1.6.3 1.6.3.x
djangoproject / django 1.7.6 1.7.6.x
djangoproject / django 1.8.0 1.8.0.x
djangoproject / django 1.7-rc3 1.7-rc3.x
djangoproject / django 1.5.8 1.5.8.x
djangoproject / django 1.6.4 1.6.4.x
djangoproject / django 1.6 1.6.x
djangoproject / django 1.5.9 1.5.9.x
djangoproject / django 1.6.1 1.6.1.x
djangoproject / django 1.6.2 1.6.2.x
djangoproject / django 1.6-beta1 1.6-beta1.x
djangoproject / django 1.6-beta3 1.6-beta3.x
djangoproject / django 1.7-rc1 1.7-rc1.x
djangoproject / django 1.6.9 1.6.9.x
djangoproject / django 1.7.1 1.7.1.x
djangoproject / django 1.7-beta2 1.7-beta2.x
djangoproject / django 1.5.2 1.5.2.x
djangoproject / django 1.5-alpha 1.5-alpha.x
djangoproject / django 1.5.6 1.5.6.x
djangoproject / django 1.5.11 1.5.11.x
djangoproject / django 1.7-beta4 1.7-beta4.x
oracle / solaris 11.2 11.2.x
canonical / ubuntu_linux 12.04 12.04.x
canonical / ubuntu_linux 14.10 14.10.x
canonical / ubuntu_linux 14.04 14.04.x
canonical / ubuntu_linux 10.04 10.04.x