Security Advisory

CVE-2009-2659

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-08-04 16:13:00
Last updated 2024-08-07 05:59:56
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL.