SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.
- http://blog.51cto.com/13770310/2177226
- https://github.com/sfh320/seacms/issues/1
No PoCs found on GitHub currently.