Vulnerabilities (CVE)

Filtered by vendor Webhost Automation Subscribe
Filtered by product Helm Control Panel
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-1499 1 Webhost Automation 1 Helm Control Panel 2024-11-20 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.
CVE-2004-1498 1 Webhost Automation 1 Helm Control Panel 2024-11-20 7.5 HIGH N/A
SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.