Skip to content
Noroxi

hola records

4 published records for vendor hola.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 17
  2. 18

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

All records

4 records
  • CVE-2018-6623
    35Monitor

    An issue was discovered in Hola 1.79.859.

    HighCVSS 8.8No exploitEPSS 1%

    hola · vpnMar 12, 2018

  • Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a Trojan horse 7za.exe

    HighCVSS 7.8No exploitEPSS 0%

    hola · vpnNov 9, 2017

  • CVE-2005-0796
    21Monitor

    Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a

    MediumCVSS 5.0Proof of conceptEPSS 3%

    hola · holacmsMay 2, 2005

  • CVE-2005-0795
    21Monitor

    HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a

    MediumCVSS 5.0Proof of conceptEPSS 2%

    hola · holacmsMar 14, 2005