Vulnerabilities > Webhost Automation > Helm WEB Hosting Control Panel > 3.2.10

DATE CVE VULNERABILITY TITLE RISK
2006-11-20 CVE-2006-5984 Cross-Site Scripting vulnerability in Webhost Automation Helm web Hosting Control Panel 3.2.10
Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) txtCompanyName, (2) txtEmail, or (3) txtUserAccNum parameter to (a) users.asp, or the (4) setThemeColour parameter to (b) default.asp in the Reseller and Admin levels; or the (5) setThemeColour parameter to default.asp in the User level.
6.8