CVE-2019-16867
25.09.2019, 12:15
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774. (If the attacker deletes config.php and visits install/index.php, they can reinstall the product.)
Vendor | Product | Version |
---|---|---|
hongcms_project | hongcms | 3.0.0 |
𝑥
= Vulnerable software versions