Critical severity9.8NVD Advisory· Published May 14, 2021· Updated Jun 17, 2026
CVE-2020-18166
CVE-2020-18166
Description
Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "admin/wenjian.php?wj=../templets/pc".
Affected products
3cpe:2.3:a:laobancms:laobancms:2.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:laobancms:laobancms:2.0:*:*:*:*:*:*:*
- (no CPE)range: =2.0
- LAOBANCMS/LAOBANCMSdescription
Patches
Vulnerability mechanics
References
1- github.com/Cumtyuanfeng/Laobancms/blob/master/vuln.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.