#VU15940 Path traversal in SeaCMS - CVE-2018-16821
Published: November 18, 2018
SeaCMS
SeaCMS .Net
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences passed via the "path" HTTP GET parameter to "upload/admin/admin_template.php" script. A remote attacker can send a specially crafted HTTP request and list contents of arbitrary directory on the system.