Description
The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.
Remediation
References
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4402)
WordPress Plugin Responsive Poll Security Bypass (1.3.4)
MySQL Out-of-bounds Write Vulnerability (CVE-2009-4484)
MySQL CVE-2018-3161 Vulnerability (CVE-2018-3161)
SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-1443)