The WebUI component in Deluge before 1.3.15 contains a directory traversal vulnerability involving a request in which the name of the render file is not associated with any template file.
https://bugs.debian.org/862611
http://www.securityfocus.com/bid/99099