Vulnerabilities > CVE-2005-0796
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | HolaCMS 1.2.x/1.4.x Voting Module Directory Traversal Remote File Corruption Vulnerability. CVE-2005-0796. Webapps exploit for php platform |
id | EDB-ID:25222 |
last seen | 2016-02-03 |
modified | 2005-03-13 |
published | 2005-03-13 |
reporter | Virginity Security |
source | https://www.exploit-db.com/download/25222/ |
title | HolaCMS 1.2.x/1.4.x Voting Module Directory Traversal Remote File Corruption Vulnerability |