Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
laobancms vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2020-18165
Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote malicious users to execute arbitrary code by injecting commands into the "Website SEO Keywords" field on the page "admin/info.php?shuyu".
Laobancms Laobancms 2.0
7.5
CVSSv2
CVE-2020-18166
Unrestricted File Upload in LAOBANCMS v2.0 allows remote malicious users to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "admin/wenjian.php?wj=../templets/pc".
Laobancms Laobancms 2.0
3.5
CVSSv2
CVE-2020-18167
Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote malicious users to execute arbitrary code by injecting commands into the "Homepage Introduction" field of component "admin/info.php?shuyu".
Laobancms Laobancms 2.0
7.5
CVSSv2
CVE-2018-19220
An issue exists in LAOBANCMS 2.0. It allows remote malicious users to execute arbitrary PHP code via the host parameter to the install/ URI.
Laobancms Laobancms 2.0
7.5
CVSSv2
CVE-2018-19222
An issue exists in LAOBANCMS 2.0. It allows a /install/mysql_hy.php?riqi=0&i=0 attack to reset the admin password, even if install.txt exists.
Laobancms Laobancms 2.0
5
CVSSv2
CVE-2018-19224
An issue exists in LAOBANCMS 2.0. /admin/login.php allows spoofing of the id and guanliyuan cookies.
Laobancms Laobancms 2.0
6.8
CVSSv2
CVE-2018-19225
An issue exists in LAOBANCMS 2.0. admin/mima.php has CSRF.
Laobancms Laobancms 2.0
3.5
CVSSv2
CVE-2018-19227
An issue exists in LAOBANCMS 2.0. It allows XSS via the admin/liuyan.php neirong[] parameter.
Laobancms Laobancms 2.0
6.4
CVSSv2
CVE-2018-19228
An issue exists in LAOBANCMS 2.0. It allows arbitrary file deletion via ../ directory traversal in the admin/pic.php del parameter, as demonstrated by deleting install/install.txt to permit a reinstallation.
Laobancms Laobancms 2.0
3.5
CVSSv2
CVE-2018-19229
An issue exists in LAOBANCMS 2.0. It allows XSS via the admin/art.php?typeid=1 biaoti parameter.
Laobancms Laobancms 2.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-33545
CVE-2024-35725
CVE-2024-32704
overflow
file upload
CVE-2024-0230
CVE-2024-32705
CVE-2024-23692
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »