VYPR

lms

by Lan Management System

CVEs (3)

  • CVE-2018-1000535HigJun 26, 2018
    risk 0.49cvss 7.5epss 0.02

    lms version <= LMS_011123 contains a Local File Disclosure vulnerability in File reading functionality in LMS module that can result in Possible to read files on the server. This attack appear to be exploitable via GET parameter. This vulnerability appears to have been fixed in…

  • CVE-2007-1643Mar 24, 2007
    risk 0.04cvss —epss 0.11

    Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2) _LIB_DIR parameter to…

  • CVE-2007-2198Apr 24, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in LAN Management System (LMS) before 1.6.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably involving the OD parameter to contrib/formularz_przelewu_wplaty/druk.php.