Vulnerabilities > CVE-2005-0796

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
hola
exploit available

Summary

Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.

Vulnerable Configurations

Part Description Count
Application
Hola
2

Exploit-Db

descriptionHolaCMS 1.2.x/1.4.x Voting Module Directory Traversal Remote File Corruption Vulnerability. CVE-2005-0796. Webapps exploit for php platform
idEDB-ID:25222
last seen2016-02-03
modified2005-03-13
published2005-03-13
reporterVirginity Security
sourcehttps://www.exploit-db.com/download/25222/
titleHolaCMS 1.2.x/1.4.x Voting Module Directory Traversal Remote File Corruption Vulnerability