CVE-2012-4520

Source
https://nvd.nist.gov/vuln/detail/CVE-2012-4520
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2012-4520.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2012-4520
Aliases
Downstream
Published
2012-11-18T23:55:01Z
Modified
2025-08-09T20:01:28Z
Summary
[none]
Details

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

References

Affected packages