CVE-2018-17365

SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.
References
Link Resource
http://blog.51cto.com/13770310/2177226 Exploit Third Party Advisory
https://github.com/sfh320/seacms/issues/1 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:seacms:seacms:6.64:*:*:*:*:*:*:*
cpe:2.3:a:seacms:seacms:7.2:*:*:*:*:*:*:*

History

19 Apr 2022, 16:11

Type Values Removed Values Added
CPE cpe:2.3:a:seacms:seacms:7.2:*:*:*:*:*:*:*
References
  • (MISC) https://github.com/sfh320/seacms/issues/1 - Exploit, Third Party Advisory

17 Aug 2021, 19:15

Type Values Removed Values Added
Summary SeaCMS 6.64 allows remote attackers to delete arbitrary files via the filedir parameter. SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.

Information

Published : 2018-09-26 21:29

Updated : 2024-02-04 20:03


NVD link : CVE-2018-17365

Mitre link : CVE-2018-17365

CVE.ORG link : CVE-2018-17365


JSON object : View

Products Affected

seacms

  • seacms
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')