WebHost Automation Helm Control Panel Multiple Input Validation Vulnerabilities
BID:11586
Info
WebHost Automation Helm Control Panel Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 11586 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 02 2004 12:00AM |
| Updated: | Nov 02 2004 12:00AM |
| Credit: | Discovery is credited to Behrang Fouladi <[email protected]>. |
| Vulnerable: |
WebHost Automation Helm Control Panel 3.1.19 WebHost Automation Helm Control Panel 3.1.18 WebHost Automation Helm Control Panel 3.1.17 WebHost Automation Helm Control Panel 3.1.16 WebHost Automation Helm Control Panel 3.1.15 WebHost Automation Helm Control Panel 3.1.14 WebHost Automation Helm Control Panel 3.1.13 WebHost Automation Helm Control Panel 3.1.12 WebHost Automation Helm Control Panel 3.1.11 WebHost Automation Helm Control Panel 3.1.10 |
| Not Vulnerable: |
WebHost Automation Helm Control Panel 3.1.20 |
Discussion
WebHost Automation Helm Control Panel Multiple Input Validation Vulnerabilities
Helm Control Panel is reported prone to multiple vulnerabilities. These include an SQL injection issue and an HTML injection vulnerability. A remote attacker can execute arbitrary HTML and script code in a user's browser. Manipulation of SQL queries to reveal or corrupt sensitive database data is possible as well.
Helm Control Panel versions 3.1.19 and prior are reported vulnerable to these issues.
Helm Control Panel is reported prone to multiple vulnerabilities. These include an SQL injection issue and an HTML injection vulnerability. A remote attacker can execute arbitrary HTML and script code in a user's browser. Manipulation of SQL queries to reveal or corrupt sensitive database data is possible as well.
Helm Control Panel versions 3.1.19 and prior are reported vulnerable to these issues.
Exploit / POC
WebHost Automation Helm Control Panel Multiple Input Validation Vulnerabilities
No exploit is required.
The following proof of concept was provided:
xxxx',10,0); insert into account(accountnumber,accounttype,accountpassword) values('root',0,'');--
No exploit is required.
The following proof of concept was provided:
xxxx',10,0); insert into account(accountnumber,accounttype,accountpassword) values('root',0,'');--
Solution / Fix
WebHost Automation Helm Control Panel Multiple Input Validation Vulnerabilities
Solution:
The vendor has released Helm Control Panel 3.1.20 to address these issues. Please contact the vendor to obtain a fixed version.
Solution:
The vendor has released Helm Control Panel 3.1.20 to address these issues. Please contact the vendor to obtain a fixed version.
References
WebHost Automation Helm Control Panel Multiple Input Validation Vulnerabilities
References:
References:
- Helm Control Panel Product Page (WebHost Automation)
- [Hat-Squad] SQL injection and XSS Vulnerabilities in HELM (Hat-Squad Security Team
)