{"api_version":"1","generated_at":"2026-07-23T08:04:30+00:00","cve":"CVE-2007-5251","urls":{"html":"https://cve.report/CVE-2007-5251","api":"https://cve.report/api/cve/CVE-2007-5251.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5251","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5251"},"summary":{"title":"CVE-2007-5251","description":"Multiple cross-site scripting (XSS) vulnerabilities in Helm 3.2.16 allow remote attackers to inject arbitrary web script or HTML via (1) the showOption parameter to domain.asp, or the (2) Folder or (3) StartPath parameter to FileManager.asp.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-10-06 17:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-352","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36962","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36962","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://pridels-team.blogspot.com/2007/10/helm-xss-vuln.html","name":"http://pridels-team.blogspot.com/2007/10/helm-xss-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"-UNSECURED SYSTEMS-: Helm XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25940","name":"http://www.securityfocus.com/bid/25940","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Web Host Automation Helm Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/27080","name":"http://secunia.com/advisories/27080","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Helm Web Hosting Control Panel Cross-Site Scripting Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5251","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5251","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5251","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"webhost_automation","cpe5":"helm_web_hosting_control_panel","cpe6":"3.2.16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:24:41.852Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels-team.blogspot.com/2007/10/helm-xss-vuln.html"},{"name":"25940","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25940"},{"name":"helm-domain-filemanager-xss(36962)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36962"},{"name":"27080","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27080"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-10-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Helm 3.2.16 allow remote attackers to inject arbitrary web script or HTML via (1) the showOption parameter to domain.asp, or the (2) Folder or (3) StartPath parameter to FileManager.asp."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://pridels-team.blogspot.com/2007/10/helm-xss-vuln.html"},{"name":"25940","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25940"},{"name":"helm-domain-filemanager-xss(36962)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36962"},{"name":"27080","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27080"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5251","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Helm 3.2.16 allow remote attackers to inject arbitrary web script or HTML via (1) the showOption parameter to domain.asp, or the (2) Folder or (3) StartPath parameter to FileManager.asp."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://pridels-team.blogspot.com/2007/10/helm-xss-vuln.html","refsource":"MISC","url":"http://pridels-team.blogspot.com/2007/10/helm-xss-vuln.html"},{"name":"25940","refsource":"BID","url":"http://www.securityfocus.com/bid/25940"},{"name":"helm-domain-filemanager-xss(36962)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36962"},{"name":"27080","refsource":"SECUNIA","url":"http://secunia.com/advisories/27080"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5251","datePublished":"2007-10-06T17:00:00.000Z","dateReserved":"2007-10-06T00:00:00.000Z","dateUpdated":"2024-08-07T15:24:41.852Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-10-06 17:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-352","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:webhost_automation:helm_web_hosting_control_panel:3.2.16:*:*:*:*:*:*:*","matchCriteriaId":"01DF1866-DB95-4A4E-AD3B-6360D879A209"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5251","Ordinal":"1","Title":"CVE-2007-5251","CVE":"CVE-2007-5251","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5251","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Helm 3.2.16 allow remote attackers to inject arbitrary web script or HTML via (1) the showOption parameter to domain.asp, or the (2) Folder or (3) StartPath parameter to FileManager.asp.","Type":"Description","Title":"CVE-2007-5251"},{"CveYear":"2007","CveId":"5251","Ordinal":"2","NoteData":"2007-10-06","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5251","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}