Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-0696 | First vendor Publication | 2011-02-14 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged AJAX requests that leverage a "combination of browser plugins and redirects," a related issue to CVE-2011-0447. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0696 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-352 | Cross-Site Request Forgery (CSRF) (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2011-09-12 | Name : Fedora Update for audacious-plugins FEDORA-2011-12350 File : nvt/gb_fedora_2011_12350_audacious-plugins_fc15.nasl |
2011-03-09 | Name : Debian Security Advisory DSA 2163-2 (dajaxice) File : nvt/deb_2163_2.nasl |
2011-03-07 | Name : Debian Security Advisory DSA 2163-1 (python-django) File : nvt/deb_2163_1.nasl |
2011-02-22 | Name : Fedora Update for Django FEDORA-2011-1235 File : nvt/gb_fedora_2011_1235_Django_fc14.nasl |
2011-02-22 | Name : Fedora Update for Django FEDORA-2011-1261 File : nvt/gb_fedora_2011_1261_Django_fc13.nasl |
2011-02-22 | Name : Mandriva Update for python-django MDVSA-2011:031 (python-django) File : nvt/gb_mandriva_MDVSA_2011_031.nasl |
2011-02-18 | Name : Ubuntu Update for python-django vulnerabilities USN-1066-1 File : nvt/gb_ubuntu_USN_1066_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
70999 | Django X-Requested-With Header CSRF Django contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not properly validate HTTP requests that contain an X-Requested-With header. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may use a forged Ajax request to trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2011-02-20 | Name : The remote Fedora host is missing a security update. File : fedora_2011-1235.nasl - Type : ACT_GATHER_INFO |
2011-02-20 | Name : The remote Fedora host is missing a security update. File : fedora_2011-1261.nasl - Type : ACT_GATHER_INFO |
2011-02-20 | Name : The remote Mandriva Linux host is missing a security update. File : mandriva_MDVSA-2011-031.nasl - Type : ACT_GATHER_INFO |
2011-02-18 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-1066-1.nasl - Type : ACT_GATHER_INFO |
2011-02-15 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2163.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:06:05 |
|
2024-11-28 12:24:48 |
|
2021-05-04 12:13:59 |
|
2021-04-22 01:15:09 |
|
2020-05-23 00:27:47 |
|
2016-04-26 20:32:43 |
|
2014-02-17 11:00:27 |
|
2013-05-10 22:54:31 |
|