5
CVSSv2

CVE-2005-0796

Published: 02/05/2005 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote malicious users to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.

Vulnerable Product Search on Vulmon Subscribe to Product

Exploits

source: wwwsecurityfocuscom/bid/12799/info HolaCMS is prone to a vulnerability that may allow remote users to corrupt files on the server This issue is similar to the vulnerability described in BID 12789 (HolaCMS Voting Module Remote File Corruption Vulnerability) It is reported that HolaCMS 149-1, which was released to address the i ...