VYPR
High severity7.5NVD Advisory· Published Nov 12, 2018· Updated Jun 17, 2026

CVE-2018-19228

CVE-2018-19228

Description

An issue was discovered in LAOBANCMS 2.0. It allows arbitrary file deletion via ../ directory traversal in the admin/pic.php del parameter, as demonstrated by deleting install/install.txt to permit a reinstallation.

Affected products

3
  • Laoban CMS/Laobancmsinferred3 versions
    = 2.0+ 2 more
    • (no CPE)range: = 2.0
    • cpe:2.3:a:laobancms:laobancms:2.0:*:*:*:*:*:*:*
    • (no CPE)range: =2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.