Vulnerabilities > CVE-2006-1407 - Unspecified vulnerability in Webhost Automation Helm web Hosting Control Panel

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
webhost-automation
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp.

Vulnerable Configurations

Part Description Count
Application
Webhost_Automation
1

Exploit-Db

  • descriptionWeb Host Automation Ltd. Helm 3.2.10 beta domains.asp txtDomainName Parameter XSS. CVE-2006-1407. Webapps exploit for asp platform
    idEDB-ID:27486
    last seen2016-02-03
    modified2006-03-27
    published2006-03-27
    reporterr0t
    sourcehttps://www.exploit-db.com/download/27486/
    titleWeb Host Automation Ltd. Helm 3.2.10 beta domains.asp txtDomainName Parameter XSS
  • descriptionWeb Host Automation Ltd. Helm 3.2.10 beta default.asp Multiple Parameter XSS. CVE-2006-1407. Webapps exploit for asp platform
    idEDB-ID:27487
    last seen2016-02-03
    modified2006-03-27
    published2006-03-27
    reporterr0t
    sourcehttps://www.exploit-db.com/download/27487/
    titleWeb Host Automation Ltd. Helm 3.2.10 beta default.asp Multiple Parameter XSS