Vulnerabilities > CVE-2006-1407 - Cross-Site Scripting vulnerability in Web Host Automation Ltd. Helm

047910
CVSS 5.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
webhost-automation
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp. These issues are reportedly fixed by the vendor. Version 3.2.10-stable will contain these fixes when it is released. Contact the vendor for further information on obtaining fixes.

Vulnerable Configurations

Part Description Count
Application
Webhost_Automation
1

Exploit-Db

  • descriptionWeb Host Automation Ltd. Helm 3.2.10 beta domains.asp txtDomainName Parameter XSS. CVE-2006-1407. Webapps exploit for asp platform
    idEDB-ID:27486
    last seen2016-02-03
    modified2006-03-27
    published2006-03-27
    reporterr0t
    sourcehttps://www.exploit-db.com/download/27486/
    titleWeb Host Automation Ltd. Helm 3.2.10 beta domains.asp txtDomainName Parameter XSS
  • descriptionWeb Host Automation Ltd. Helm 3.2.10 beta default.asp Multiple Parameter XSS. CVE-2006-1407. Webapps exploit for asp platform
    idEDB-ID:27487
    last seen2016-02-03
    modified2006-03-27
    published2006-03-27
    reporterr0t
    sourcehttps://www.exploit-db.com/download/27487/
    titleWeb Host Automation Ltd. Helm 3.2.10 beta default.asp Multiple Parameter XSS