VYPR
Vendor

Hola

Products
4
CVEs
5
Across products
7
Status
Private

Products

4

Recent CVEs

5
  • CVE-2018-6623HigMar 12, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Hola 1.79.859. An unprivileged user could modify or overwrite the executable with arbitrary code, which would be executed the next time the service is started. Depending on the user that the service runs as, this could result in privilege escalation.…

  • CVE-2017-16757HigNov 9, 2017
    risk 0.51cvss 7.8epss 0.00

    Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a Trojan horse 7za.exe or hola.exe file.

  • CVE-2005-0796May 2, 2005
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.

  • CVE-2005-0795Mar 14, 2005
    risk 0.03cvss epss 0.02

    HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.

  • CVE-2007-1977Apr 12, 2007
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in index_cms.php in holaCMS 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter.