CVE-2005-0796
N/A
N/A
Summary
Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.holacms.de/?content=changelog
- http://secunia.com/advisories/14566
- http://marc.info/?l=bugtraq&m=111090966815089&w=2
References
- http://www.holacms.de/?content=changelog
- http://secunia.com/advisories/14566
- http://marc.info/?l=bugtraq&m=111090966815089&w=2
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.