laobancms CVE Vulnerabilities & CVE List (14)

Products (CPE): — CVEs: 14

laobancms vulnerability overview

Aggregates CVE and security vulnerability intelligence across all laobancms-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk path handling and related security problems, affecting vendor surface production workloads and vendor surface software deployment scenarios.

Vulnerability distribution trend (last 24 months)

Showing 114 of 14 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2020-18167 Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Homepage Introduction" field of component "admin/info.php?shuyu". [email protected] 4.8 0.86% 2021-05-14 2024-11-21
CVE-2020-18166 Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "admin/wenjian.php?wj=../templets/pc". [email protected] 9.8 1.68% 2021-05-14 2024-11-21
CVE-2020-18165 Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Website SEO Keywords" field on the page "admin/info.php?shuyu". [email protected] 4.8 0.91% 2021-05-12 2024-11-21
CVE-2018-19328 LAOBANCMS 2.0 allows install/mysql_hy.php?riqi=../ Directory Traversal. [email protected] 9.8 1.75% 2018-11-17 2024-11-21
CVE-2018-19229 An issue was discovered in LAOBANCMS 2.0. It allows XSS via the admin/art.php?typeid=1 biaoti parameter. [email protected] 5.4 0.56% 2018-11-12 2024-11-21
CVE-2018-19228 An issue was discovered in LAOBANCMS 2.0. It allows arbitrary file deletion via ../ directory traversal in the admin/pic.php del parameter, as demonstrated by deleting install/install.txt to permit a reinstallation. [email protected] 7.5 1.54% 2018-11-12 2024-11-21
CVE-2018-19227 An issue was discovered in LAOBANCMS 2.0. It allows XSS via the admin/liuyan.php neirong[] parameter. [email protected] 5.4 0.56% 2018-11-12 2024-11-21
CVE-2018-19226 An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to list .txt files via a direct request for the /data/0/admin.txt URI. [email protected] 5.3 1.18% 2018-11-12 2024-11-21
CVE-2018-19225 An issue was discovered in LAOBANCMS 2.0. admin/mima.php has CSRF. [email protected] 8.8 0.52% 2018-11-12 2024-11-21
CVE-2018-19224 An issue was discovered in LAOBANCMS 2.0. /admin/login.php allows spoofing of the id and guanliyuan cookies. [email protected] 7.5 0.98% 2018-11-12 2024-11-21
CVE-2018-19223 An issue was discovered in LAOBANCMS 2.0. It allows XSS via the first input field to the admin/type.php?id=1 URI. [email protected] 4.8 0.56% 2018-11-12 2024-11-21
CVE-2018-19222 An issue was discovered in LAOBANCMS 2.0. It allows a /install/mysql_hy.php?riqi=0&i=0 attack to reset the admin password, even if install.txt exists. [email protected] 9.8 1.42% 2018-11-12 2024-11-21
CVE-2018-19221 An issue was discovered in LAOBANCMS 2.0. It allows SQL Injection via the admin/login.php guanliyuan parameter. [email protected] 9.8 1.20% 2018-11-12 2024-11-21
CVE-2018-19220 An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI. [email protected] 9.8 1.67% 2018-11-12 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence