Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) txtCompanyName, (2) txtEmail, or (3) txtUserAccNum parameter to (a) users.asp, or the (4) setThemeColour parameter to (b) default.asp in the Reseller and Admin levels; or the (5) setThemeColour parameter to default.asp in the User level. NOTE: the txtDomainName parameter to domains.asp is covered by CVE-2006-1407, which suggests that this vector is fixed in 3.2.10 stable.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2006-11-20T21:00:00
Updated: 2024-08-07T20:12:31.190Z
Reserved: 2006-11-20T00:00:00
Link: CVE-2006-5984
Vulnrichment
No data.
NVD
Status : Modified
Published: 2006-11-20T21:07:00.000
Modified: 2024-11-21T00:21:22.420
Link: CVE-2006-5984
Redhat
No data.