CVE-2011-0698 Information
Feb 14, 2021
cve
Description
Directory traversal vulnerability in Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 on Windows might allow remote attackers to read or execute files via a / (slash) character in a key in a session cookie related to session replays.
Reference
http://openwall.com/lists/oss-security/2011/02/09/6 http://secunia.com/advisories/43230 http://www.djangoproject.com/weblog/2011/feb/08/security/ http://www.mandriva.com/security/advisories?name=MDVSA-2011:031 http://www.securityfocus.com/bid/46296 http://www.vupen.com/english/advisories/2011/0372 http://www.vupen.com/english/advisories/2011/0439
Share on: