CVE-2012-4520

Source
https://cve.org/CVERecord?id=CVE-2012-4520
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2012-4520.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2012-4520
Aliases
Downstream
Withdrawn
2026-01-27T04:11:20.785928Z
Published
2012-11-18T23:55:01Z
Modified
2026-01-27T04:11:20.785928Z
Summary
[none]
Details

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

References

Affected packages