7.5
CVE-2004-1498
- EPSS 0.5%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Webhost Automation ≫ Helm Control Panel Version3.1.10
Webhost Automation ≫ Helm Control Panel Version3.1.11
Webhost Automation ≫ Helm Control Panel Version3.1.12
Webhost Automation ≫ Helm Control Panel Version3.1.13
Webhost Automation ≫ Helm Control Panel Version3.1.14
Webhost Automation ≫ Helm Control Panel Version3.1.15
Webhost Automation ≫ Helm Control Panel Version3.1.16
Webhost Automation ≫ Helm Control Panel Version3.1.17
Webhost Automation ≫ Helm Control Panel Version3.1.18
Webhost Automation ≫ Helm Control Panel Version3.1.19
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.5% | 0.632 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|