CVE-2018-16343: Code Injection
Published Sep 2, 2018
·Updated
SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.
Affected Software
1 affected component
SEACMS SEACMS=6.61
Event History
Sep 2, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for SeaCMS 6.61?
The vulnerability ID for SeaCMS 6.61 is CVE-2018-16343.
2
What is the severity rating of CVE-2018-16343?
CVE-2018-16343 has a severity rating of 7.2 (High).
3
How can remote attackers exploit CVE-2018-16343?
Remote attackers can exploit CVE-2018-16343 to execute arbitrary code.
4
What software version is affected by CVE-2018-16343?
SeaCMS 6.61 is affected by CVE-2018-16343.
5
Is there a fix available for CVE-2018-16343?
There may not be an official fix available for CVE-2018-16343. It is recommended to apply any patches or security updates provided by the vendor.