Description
HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Virginity Security · htmlwebappsphp
https://www.exploit-db.com/exploits/25217
References (4)
Scores
EPSS
0.0483
EPSS Percentile
89.5%
Details
Status
published
Products (14)
hola/holacms
1.2.9
hola/holacms
1.2.10
hola/holacms
1.4
hola/holacms
1.4.1
hola/holacms
1.4.2
hola/holacms
1.4.2a
hola/holacms
1.4.3
hola/holacms
1.4.4
hola/holacms
1.4.5
hola/holacms
1.4.6
... and 4 more
Published
Mar 14, 2005
Tracked Since
Feb 18, 2026