Cumtyuanfeng

3 exploits Active since May 2021
CVE-2020-18165 WRITEUP MEDIUM WRITEUP
LAOBANCMS v2.0 - XSS
Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Website SEO Keywords" field on the page "admin/info.php?shuyu".
CVSS 4.8
CVE-2020-18166 WRITEUP CRITICAL WRITEUP
LAOBANCMS v2.0 - File Upload
Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "admin/wenjian.php?wj=../templets/pc".
CVSS 9.8
CVE-2020-18167 WRITEUP MEDIUM WRITEUP
LAOBANCMS v2.0 - XSS
Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Homepage Introduction" field of component "admin/info.php?shuyu".
CVSS 4.8