Back

CVE-2004-1498

SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (10)

Vendor Product Version
webhost_automation helm_control_panel 3.1.10
webhost_automation helm_control_panel 3.1.11
webhost_automation helm_control_panel 3.1.12
webhost_automation helm_control_panel 3.1.13
webhost_automation helm_control_panel 3.1.14
webhost_automation helm_control_panel 3.1.15
webhost_automation helm_control_panel 3.1.16
webhost_automation helm_control_panel 3.1.17
webhost_automation helm_control_panel 3.1.18
webhost_automation helm_control_panel 3.1.19

GitHub Security Advisory GHSA-m55m-3w7q-px94

SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.21%

Top 34% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub