Laobancms

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 14
    Known Exploited: 0
    5
    Critical Level Threats
    3
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-18167

    Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Homepage Introduction" field of component "admin/info.php?shuyu".

    Last Modified: Nov 21, 2024
    Published: May 14, 2021

    CVE-2020-18166

    Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "admin/wenjian.php?wj=../templets/pc".

    Last Modified: Nov 21, 2024
    Published: May 14, 2021

    CVE-2020-18165

    Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Website SEO Keywords" field on the page "admin/info.php?shuyu".

    Last Modified: Nov 21, 2024
    Published: May 12, 2021

    CVE-2018-19328

    LAOBANCMS 2.0 allows install/mysql_hy.php?riqi=../ Directory Traversal.

    Last Modified: Nov 21, 2024
    Published: Nov 17, 2018

    CVE-2018-19226

    An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to list .txt files via a direct request for the /data/0/admin.txt URI.

    Last Modified: Nov 21, 2024
    Published: Nov 12, 2018
    Items Per Page