CVE-2005-0795 describes a critical vulnerability in HolaCMS versions 1.2 and 1.4.x, specifically within its voting module, where insufficient file access restrictions in the holaDB/votes directory allow remote attackers to overwrite arbitrary files by manipulating the vote_filename parameter. This vulnerability carries a CVSS score of 5.0, indicating a medium severity, and allows for data integrity compromise (I:P) with low attack complexity (AC:L) and no authentication required (Au:N). While there is no evidence of active exploitation or Metasploit modules, an exploit is publicly available on ExploitDB (EDB-25217), and despite its age, its FAUCET Risk Score of 80/100 suggests a significant potential impact if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.9CPE matchmatch criteria | cpe:2.3:a:hola:holacms:1.2.9:*:*:*:*:*:*:* | ||
1.2.10CPE matchmatch criteria | cpe:2.3:a:hola:holacms:1.2.10:*:*:*:*:*:*:* | ||
1.4CPE matchmatch criteria | cpe:2.3:a:hola:holacms:1.4:*:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:a:hola:holacms:1.4.1:*:*:*:*:*:*:* | ||
1.4.2CPE matchmatch criteria | cpe:2.3:a:hola:holacms:1.4.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.