CVE-2004-1499
Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.
- Affected products
- Helm
- Webhost Automation Helm Control Panel
- = 3.1.10, 3.1.11, 3.1.12, 3.1.13, 3.1.14, 3.1.15, 3.1.16, 3.1.17, 3.1.18, 3.1.19
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.8% (76th percentile)
- NVD status
- Modified
- Published
- 2005-02-19
CVE-2004-1499 at NVD
1 known exploit for CVE-2004-1499
Proof-of-concept code and exploit modules indexed by Sploitus