Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2004-1499 1 Webhost Automation 1 Helm Control Panel 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.
CVE-2004-1498 1 Webhost Automation 1 Helm Control Panel 2025-04-03 N/A
SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.