Vulnerability: LAOBANCMS 2.0 Admin Password Reset via /install/mysql_hy.php?riqi=0&i=0 Attack

Vulnerability: LAOBANCMS 2.0 Admin Password Reset via /install/mysql_hy.php?riqi=0&i=0 Attack

CVE-2018-19222 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

An issue was discovered in LAOBANCMS 2.0. It allows a /install/mysql_hy.php?riqi=0&i=0 attack to reset the admin password, even if install.txt exists.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.