An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI.
- https://github.com/AvaterXXX/laobanCMS/blob/master/1.md#getshell
No PoCs found on GitHub currently.