7.5
CVE-2004-1498
- EPSS 0.5%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Webhost Automation ≫ Helm Control Panel Version3.1.10
Webhost Automation ≫ Helm Control Panel Version3.1.11
Webhost Automation ≫ Helm Control Panel Version3.1.12
Webhost Automation ≫ Helm Control Panel Version3.1.13
Webhost Automation ≫ Helm Control Panel Version3.1.14
Webhost Automation ≫ Helm Control Panel Version3.1.15
Webhost Automation ≫ Helm Control Panel Version3.1.16
Webhost Automation ≫ Helm Control Panel Version3.1.17
Webhost Automation ≫ Helm Control Panel Version3.1.18
Webhost Automation ≫ Helm Control Panel Version3.1.19
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.5% | 0.632 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|