mirror of
https://github.com/0xMarcio/cve.git
synced 2026-03-07 08:10:58 +00:00
731 B
731 B
CVE-2016-2513
Description
The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.
POC
Reference
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.ubuntu.com/usn/USN-2915-2
Github
No PoCs found on GitHub currently.