{"api_version":"1","generated_at":"2026-07-23T08:54:12+00:00","cve":"CVE-2006-1407","urls":{"html":"https://cve.report/CVE-2006-1407","api":"https://cve.report/api/cve/CVE-2006-1407.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1407","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1407"},"summary":{"title":"CVE-2006-1407","description":"Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-03-28 11:06:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/17263","name":"http://www.securityfocus.com/bid/17263","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Web Host Automation Ltd. Helm Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://pridels0.blogspot.com/2006/03/helm-web-hosting-control-panel-xss.html","name":"http://pridels0.blogspot.com/2006/03/helm-web-hosting-control-panel-xss.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: Helm Web Hosting Control Panel XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25470","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25470","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/24126","name":"http://www.osvdb.org/24126","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/24125","name":"http://www.osvdb.org/24125","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2006/1093","name":"http://www.vupen.com/english/advisories/2006/1093","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://attrition.org/pipermail/vim/2006-March/000654.html","name":"http://attrition.org/pipermail/vim/2006-March/000654.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[VIM] Helm Control Panel followup","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19375","name":"http://secunia.com/advisories/19375","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Helm Web Hosting Control Panel Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30309","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30309","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1407","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1407","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1407","vulnerable":"1","versionEndIncluding":"3.2.10","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"webhost_automation","cpe5":"helm_web_hosting_control_panel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1407","cve":"CVE-2006-1407","epss":"0.011650000","percentile":"0.786450000","score_date":"2026-04-19","updated_at":"2026-04-20 00:11:20"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:12:21.312Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2006-1093","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1093"},{"name":"24125","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/24125"},{"name":"24126","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/24126"},{"name":"19375","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19375"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2006/03/helm-web-hosting-control-panel-xss.html"},{"name":"17263","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17263"},{"name":"helm-domainsusersdefaault-xss(30309)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30309"},{"name":"helm-domainsdefault-xss(25470)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25470"},{"name":"20060327 Helm Control Panel followup","tags":["mailing-list","x_refsource_VIM","x_transferred"],"url":"http://attrition.org/pipermail/vim/2006-March/000654.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-03-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2006-1093","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1093"},{"name":"24125","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/24125"},{"name":"24126","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/24126"},{"name":"19375","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19375"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2006/03/helm-web-hosting-control-panel-xss.html"},{"name":"17263","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17263"},{"name":"helm-domainsusersdefaault-xss(30309)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30309"},{"name":"helm-domainsdefault-xss(25470)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25470"},{"name":"20060327 Helm Control Panel followup","tags":["mailing-list","x_refsource_VIM"],"url":"http://attrition.org/pipermail/vim/2006-March/000654.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1407","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-1093","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1093"},{"name":"24125","refsource":"OSVDB","url":"http://www.osvdb.org/24125"},{"name":"24126","refsource":"OSVDB","url":"http://www.osvdb.org/24126"},{"name":"19375","refsource":"SECUNIA","url":"http://secunia.com/advisories/19375"},{"name":"http://pridels0.blogspot.com/2006/03/helm-web-hosting-control-panel-xss.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2006/03/helm-web-hosting-control-panel-xss.html"},{"name":"17263","refsource":"BID","url":"http://www.securityfocus.com/bid/17263"},{"name":"helm-domainsusersdefaault-xss(30309)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30309"},{"name":"helm-domainsdefault-xss(25470)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25470"},{"name":"20060327 Helm Control Panel followup","refsource":"VIM","url":"http://attrition.org/pipermail/vim/2006-March/000654.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1407","datePublished":"2006-03-28T11:00:00.000Z","dateReserved":"2006-03-28T00:00:00.000Z","dateUpdated":"2024-08-07T17:12:21.312Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-03-28 11:06:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:webhost_automation:helm_web_hosting_control_panel:*:*:*:*:*:*:*:*","versionEndIncluding":"3.2.10","matchCriteriaId":"50A739F0-A063-4BB6-8492-BC10B243A7EC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1407","Ordinal":"1","Title":"CVE-2006-1407","CVE":"CVE-2006-1407","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1407","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp.","Type":"Description","Title":"CVE-2006-1407"},{"CveYear":"2006","CveId":"1407","Ordinal":"2","NoteData":"2006-03-28","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1407","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}