Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Michaelwayneliu

#35001de 53,635
7.5CVSS total
Vulnerabilidades · 1
PT-2018-13573
7.5
2018-09-04
Seacms · Seacms · CVE-2018-16446
**Name of the Vulnerable Software and Affected Versions** SeaCMS versions through 6.61 **Description** An issue in SeaCMS allows remote attackers to delete arbitrary files via directory traversal sequences in the `bakfiles` parameter in the 'adm1n/admin database.php' endpoint. This can lead to the product being reinstalled by deleting 'install lock.txt'. **Recommendations** For SeaCMS versions through 6.61, consider restricting access to the 'adm1n/admin database.php' endpoint to prevent exploitation, and avoid using the `bakfiles` parameter until the issue is resolved.