CVE-2018-17365: Path Traversal
Published Sep 26, 2018
·Updated
SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.
Affected Software
2 affected components
SEACMS SEACMS=6.64
SEACMS SEACMS=7.2
Event History
Sep 26, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-17365?
CVE-2018-17365 is a vulnerability in SeaCMS 6.64 and 7.2 that allows remote attackers to delete arbitrary files via the filedir parameter.
2
How severe is CVE-2018-17365?
CVE-2018-17365 has a severity rating of 7.5, which is considered high.
3
Which versions of SeaCMS are affected by CVE-2018-17365?
SeaCMS versions 6.64 and 7.2 are affected by CVE-2018-17365.
4
How can the file deletion vulnerability in SeaCMS be exploited?
The file deletion vulnerability in SeaCMS can be exploited by sending malicious requests with a specially crafted filedir parameter.
5
Are there any references or resources available for CVE-2018-17365?
Yes, you can find more information about CVE-2018-17365 at the following references: http://blog.51cto.com/13770310/2177226 and https://github.com/sfh320/seacms/issues/1