SQL injection - Code In django
Description
Django Vulnerable to MySQL Injection The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
pypi | 1.4.11, 1.5.6, 1.6.3 | ||
debian 12 | 1.6.3-1 | ||
debian 14 | 1.6.3-1 | ||
debian 13 | 1.6.3-1 | ||
debian 11 | 1.6.3-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.