Django Improper Input Validation Vulnerability - CVE-2011-4138 - Vulnerability Database

Django Improper Input Validation Vulnerability - CVE-2011-4138

Medium
Reference: CVE-2011-4138
Title: Django Improper Input Validation Vulnerability
Overview:

The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 originally tests a URL39s validity through a HEAD request but then uses a GET request for the new target URL in the case of a redirect which might allow remote attackers to trigger arbitrary GET requests with an unintended source IP address via a crafted Location header.