ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-18166
+1 in the same advisory: …18167
Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "a

Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "admin/wenjian.php?wj=../templets/pc".

NVD description · AI analysis pending
9.8
group max
2% PoC
  • laobancms laobancms
CVE-2020-18165
Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Website SEO Keywords" field on th

Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Website SEO Keywords" field on the page "admin/info.php?shuyu".

NVD description · AI analysis pending
4.8<1% PoC
  • laobancms laobancms
CVE-2018-19328
LAOBANCMS 2.0 allows install/mysql_hy.php?riqi=../ Directory Traversal.

LAOBANCMS 2.0 allows install/mysql_hy.php?riqi=../ Directory Traversal.

NVD description · AI analysis pending
9.82% PoC
  • laobancms laobancms
CVE-2018-19220
An issue was discovered in LAOBANCMS 2.0.

An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • laobancms laobancms