Oval Definition:oval:org.mitre.oval:def:13659
Revision Date:2014-06-30Version:21
Title:USN-1066-1 -- python-django vulnerabilities
Description:It was discovered that Django did not properly validate HTTP requests that contain an X-Requested-With header. An attacker could exploit this vulnerability to perform cross-site request forgery attacks. It was discovered that Django did not properly sanitize its input when performing file uploads, resulting in cross-site scripting vulnerabilities. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2011-0696
CVE-2011-0697
USN-1066-1
USN-1066-1
Platform(s):Ubuntu 10.04
Ubuntu 10.10
Ubuntu 9.10
Product(s):python-django
Definition Synopsis
  • Release section
  • Ubuntu 10.10 is installed
  • AND Installed architecture is all
  • AND Packages section
  • python-django-doc DPKG is earlier than 1.2.3-1ubuntu0.2.10.10.2
  • OR python-django DPKG is earlier than 1.2.3-1ubuntu0.2.10.10.2
  • OR Release section
  • Ubuntu 9.10 is installed
  • AND Installed architecture is all
  • AND Packages section
  • python-django-doc DPKG is earlier than 1.1.1-1ubuntu1.2
  • OR python-django DPKG is earlier than 1.1.1-1ubuntu1.2
  • OR Release section
  • Ubuntu 10.04 is installed
  • AND Installed architecture is all
  • AND Packages section
  • python-django-doc DPKG is earlier than 1.1.1-2ubuntu1.3
  • OR python-django DPKG is earlier than 1.1.1-2ubuntu1.3
  • BACK