Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2005-0795

EPSS 4.83% · P90
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2005-0795

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
HolaCMS 投票模块 远程文件破坏漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
HOLACMS是一款基于WEB的内容管理系统。 由于一个输入验证错误,用户可以向攻击者指定的文件提交投票数据。 漏洞的起因是投票模块没有检查所提交的vote_filename变量是否位于holaDB/votes/目录中。这个漏洞可能允许远程用户破坏服务器上的文件。攻击者可以利用这个漏洞破坏HolaCMS, 还可以破坏Web Server进程环境中的任意系统文件。尽管未经确认,但应该可以通过在电脑中的破坏脚本来执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2005-0795

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2005-0795

登录查看更多情报信息。

Same Patch Batch · n/a · 2005-03-20 · 63 CVEs total

CVE-2005-0803Microsoft Windows图形设备接口库拒绝服务漏洞
CVE-2005-0817Symantec Gateway Security未明远程DNS缓存中毒漏洞
CVE-2005-0820Microsoft InfoPath 2003不安全信息存储漏洞
CVE-2005-0819Novell Netware Xsession未授权服务器控制台访问漏洞
CVE-2005-0818PunBB 跨站脚本攻击漏洞
CVE-2005-0808Apache Tomcat 拒绝服务漏洞
CVE-2005-0807Massimiliano Montoro Cain & Abel PSK程序远程堆缓冲区溢出漏洞
CVE-2005-0806Novell Evolution未明拒绝服务漏洞
CVE-2005-0805Subdreamer SQL注入漏洞
CVE-2005-0804MailEnable远程格式串处理漏洞
CVE-2005-0809NotifyLink Enterprise Server多个弱口令漏洞
CVE-2005-0802ACS Blog Search.ASP 跨站脚本漏洞
CVE-2005-0801Includer的includer.cgi目录遍历漏洞
CVE-2005-0800McNews install.php远程任意文件包含漏洞
CVE-2005-0799Oracle MySQL 安全漏洞
CVE-2005-0798Novell iChain Mini FTP 服务 登录用户数量错误漏洞
CVE-2005-0797Novell iChain Mini FTP Server 有效帐号名泄露漏洞
CVE-2005-0796HolaCMS目录遍历漏洞
CVE-2005-0794ZPanel 'install.php'拒绝服务攻击漏洞
CVE-2005-0793Zpanel 远程文件包含漏洞

Showing top 20 of 63 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2005-0795

No comments yet


Leave a comment