Skip to main content

Vendor/product archive

layton_technology / helpbox CVEs

Beta · best-effort

10 CVEs tagged to layton_technology / helpbox0 Critical, 2 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2012-4977

Published Dec 12, 2012

Layton Helpbox 4.4.0 allows remote attackers to discover cleartext credentials for the login page by sniffing the network.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4976

Published Dec 12, 2012

selectawasset.asp in Layton Helpbox 4.4.0 allows remote attackers to discover ODBC database credentials via an element=sys_asset_id request, which is not properly handled during c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4975

Published Dec 12, 2012

editrequestuser.asp in Layton Helpbox 4.4.0 allows remote authenticated users to change arbitrary support-ticket data via a modified sys_request_id parameter.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4972

Published Dec 12, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Layton Helpbox 4.4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) sys_solution_id, (2) sys_requ…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4971

Published Dec 12, 2012

Multiple SQL injection vulnerabilities in Layton Helpbox 4.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) reqclass parameter to editrequestenduser.asp; t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5401

Published Jan 9, 2008

Unrestricted file upload vulnerability in uploadrequest.asp in Layton HelpBox 3.7.1 allows remote authenticated users to upload and execute arbitrary ASP files, related to not pro…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5402

Published Jan 9, 2008

Multiple SQL injection vulnerabilities in Layton HelpBox 3.7.1 allow (1) remote attackers to execute arbitrary SQL commands via the sys_request_id parameter to editrequestenduser.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5403

Published Jan 9, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Layton HelpBox 3.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Forename, (2) Surna…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5404

Published Jan 9, 2008

Layton HelpBox 3.7.1 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote attackers to enumerate valid user…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2551

Published Dec 31, 2004

Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the sys_comment_id parameter in editcommentenduser.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1