5
CVSSv2

CVE-2005-0795

Published: 14/03/2005 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote malicious users to overwrite arbitrary files via a modified vote_filename parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

hola holacms 1.2.10

hola holacms 1.2.9

hola holacms 1.4.5

hola holacms 1.4.6

hola holacms 1.4.3

hola holacms 1.4.4

hola holacms 1.4

hola holacms 1.4.1

hola holacms 1.4.7

hola holacms 1.4.8

hola holacms 1.4.2

hola holacms 1.4.2a

hola holacms 1.4.9

hola holacms 1.4.9_1

Exploits

source: wwwsecurityfocuscom/bid/12789/info HolaCMS is prone to a vulnerability that may allow remote users to corrupt files on the server This is due an input validation error that allows users to submit voting data to an attacker-specified file It has been demonstrated that the issue may be exploited to compromise HolaCMS Arbitrary s ...