4.3
CVSSv2

CVE-2004-1499

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and previous versions allows remote malicious users to execute arbitrary web script or HTML via the Subject field.

Vulnerable Product Search on Vulmon Subscribe to Product

webhost automation helm control panel 3.1.15

webhost automation helm control panel 3.1.16

webhost automation helm control panel 3.1.17

webhost automation helm control panel 3.1.10

webhost automation helm control panel 3.1.18

webhost automation helm control panel 3.1.19

webhost automation helm control panel 3.1.11

webhost automation helm control panel 3.1.12

webhost automation helm control panel 3.1.13

webhost automation helm control panel 3.1.14

Exploits

source: wwwsecurityfocuscom/bid/11586/info Helm Control Panel is reported prone to multiple vulnerabilities These include an SQL injection issue and an HTML injection vulnerability A remote attacker can execute arbitrary HTML and script code in a user's browser Manipulation of SQL queries to reveal or corrupt sensitive database data is ...