Vulnerability CVE-2006-1407


Published: 2006-03-28   Modified: 2012-02-12

Description:
Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp.

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.8/10
4.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
Webhost automation -> Helm web hosting control panel 

 References:
http://www.vupen.com/english/advisories/2006/1093
http://www.securityfocus.com/bid/17263
http://secunia.com/advisories/19375
http://xforce.iss.net/xforce/xfdb/30309
http://xforce.iss.net/xforce/xfdb/25470
http://www.osvdb.org/24126
http://www.osvdb.org/24125
http://pridels0.blogspot.com/2006/03/helm-web-hosting-control-panel-xss.html
http://attrition.org/pipermail/vim/2006-March/000654.html

Copyright 2024, cxsecurity.com

 

Back to Top