The phpinfo function in SiteEngine 5.x allows remote malicious users to obtain system information by setting the action parameter to php_info in misc.php.
boka siteengine 5.0