Vulnerabilities
14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-18166 +1 in the same advisory: …18167 | Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "a Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "admin/wenjian.php?wj=../templets/pc". NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2020-18165 | Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Website SEO Keywords" field on th Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Website SEO Keywords" field on the page "admin/info.php?shuyu". NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2018-19328 | LAOBANCMS 2.0 allows install/mysql_hy.php?riqi=../ Directory Traversal. LAOBANCMS 2.0 allows install/mysql_hy.php?riqi=../ Directory Traversal. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2018-19220 | An issue was discovered in LAOBANCMS 2.0. An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — |