Описание
Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.
Уязвимые конфигурации
Конфигурация 1Версия до 1.4.9 (включая)
Одно из
cpe:2.3:a:hola:holacms:*:*:*:*:*:*:*:*
cpe:2.3:a:hola:holacms:1.4.9_1:*:*:*:*:*:*:*
EPSS
Процентиль: 87%
0.03359
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 3 лет назад
Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.
EPSS
Процентиль: 87%
0.03359
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other