The Admin media handler in core/servers/basehttp.py
in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL.
{ "nvd_published_at": "2009-08-04T16:30:00Z", "cwe_ids": [ "CWE-22" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-02-08T21:27:24Z" }