Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control...
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) txtCompanyName, (2) txtEmail, or (3) txtUserAccNum parameter to (a) users.asp, or the (4) setThemeColour parameter to (b) default.asp in the Reseller and Admin levels; or the (5) setThemeColour parameter to default.asp in the User level. NOTE: the txtDomainName parameter to domains.asp is covered by CVE-2006-1407, which suggests that this vector is fixed in 3.2.10 stable.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-5984
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/451737/100/0/threaded
- http://aria-security.net/advisory/helm.txt
- http://www.vupen.com/english/advisories/2006/4557
- http://secunia.com/advisories/22916
- http://securityreason.com/securityalert/1884
- http://securitytracker.com/id?1017240
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30309
- http://www.securityfocus.com/archive/1/451848/100/200/threaded
More from webhost automation
View All →Affected Vendor
webhost automation
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.