Critical severity9.8NVD Advisory· Published Nov 12, 2018· Updated Jun 17, 2026
CVE-2018-19220
CVE-2018-19220
Description
An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI.
Affected products
2cpe:2.3:a:laobancms:laobancms:2.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:laobancms:laobancms:2.0:*:*:*:*:*:*:*
- (no CPE)range: = 2.0
Patches
Vulnerability mechanics
References
1- github.com/AvaterXXX/laobanCMS/blob/master/1.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.