CVE-2004-1498
Published Dec 31, 2004SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.
Vendor/product archive
2 CVEs tagged to webhost_automation / helm_control_panel — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.
Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject fie…