Filtered by vendor Hola
Subscriptions
Filtered by product Holacms
Subscriptions
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2005-0795 | 1 Hola | 1 Holacms | 2024-08-07 | N/A |
HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter. | ||||
CVE-2005-0796 | 1 Hola | 1 Holacms | 2024-08-07 | N/A |
Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory. |
Page 1 of 1.