Security Advisory
CVE-2018-19197
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
An issue was discovered in XiaoCms 20141229. admincontrollerdatabase.php allows arbitrary directory deletion via admin/index.php?c=database&a=import&paths[]=../ directory traversal.