CVE Vulnerabilities

CVE-2004-1498

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.

Affected Software

NameVendorStart VersionEnd Version
Helm_control_panelWebhost_automation3.1.10 (including)3.1.10 (including)
Helm_control_panelWebhost_automation3.1.11 (including)3.1.11 (including)
Helm_control_panelWebhost_automation3.1.12 (including)3.1.12 (including)
Helm_control_panelWebhost_automation3.1.13 (including)3.1.13 (including)
Helm_control_panelWebhost_automation3.1.14 (including)3.1.14 (including)
Helm_control_panelWebhost_automation3.1.15 (including)3.1.15 (including)
Helm_control_panelWebhost_automation3.1.16 (including)3.1.16 (including)
Helm_control_panelWebhost_automation3.1.17 (including)3.1.17 (including)
Helm_control_panelWebhost_automation3.1.18 (including)3.1.18 (including)
Helm_control_panelWebhost_automation3.1.19 (including)3.1.19 (including)

References