Helpbox
Layton Technology · 11 CVEs
Layton Helpbox 4.4.0 allows remote attackers to discover cleartext credentials for the login page by sniffing the netwo…
Dec 12, 2012
selectawasset.asp in Layton Helpbox 4.4.0 allows remote attackers to discover ODBC database credentials via an element=…
Dec 12, 2012
editrequestuser.asp in Layton Helpbox 4.4.0 allows remote authenticated users to change arbitrary support-ticket data v…
Dec 12, 2012
Layton Helpbox 4.4.0 allows remote authenticated users to change the login context and gain privileges via a modified (…
Dec 12, 2012
Multiple cross-site scripting (XSS) vulnerabilities in Layton Helpbox 4.4.0 allow remote attackers to inject arbitrary…
Dec 12, 2012
Multiple SQL injection vulnerabilities in Layton Helpbox 4.4.0 allow remote attackers to execute arbitrary SQL commands…
Dec 12, 2012
Layton HelpBox 3.7.1 generates different responses depending on whether or not a username is valid in a failed login at…
Jan 9, 2008
Multiple cross-site scripting (XSS) vulnerabilities in Layton HelpBox 3.7.1 allow remote authenticated users to inject…
Jan 9, 2008
Multiple SQL injection vulnerabilities in Layton HelpBox 3.7.1 allow (1) remote attackers to execute arbitrary SQL comm…
Jan 9, 2008
Unrestricted file upload vulnerability in uploadrequest.asp in Layton HelpBox 3.7.1 allows remote authenticated users t…
Jan 9, 2008
Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands…
Nov 21, 2005
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2012-4977 | Layton Helpbox 4.4.0 allows remote attackers to discover cleartext credentials for the login page by sniffing the network. | MEDIUM | 1.19% | Dec 12, 2012 |
| CVE-2012-4976 | selectawasset.asp in Layton Helpbox 4.4.0 allows remote attackers to discover ODBC database credentials via an element=sys_asset_id request, which is not prope… | MEDIUM | 1.19% | Dec 12, 2012 |
| CVE-2012-4975 | editrequestuser.asp in Layton Helpbox 4.4.0 allows remote authenticated users to change arbitrary support-ticket data via a modified sys_request_id parameter. | MEDIUM | 0.84% | Dec 12, 2012 |
| CVE-2012-4974 | Layton Helpbox 4.4.0 allows remote authenticated users to change the login context and gain privileges via a modified (1) loggedinenduser, (2) loggedinendusern… | MEDIUM | 1.08% | Dec 12, 2012 |
| CVE-2012-4972 | Multiple cross-site scripting (XSS) vulnerabilities in Layton Helpbox 4.4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) sys_solut… | MEDIUM | 1.15% | Dec 12, 2012 |
| CVE-2012-4971 | Multiple SQL injection vulnerabilities in Layton Helpbox 4.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) reqclass parameter to editr… | HIGH | 1.19% | Dec 12, 2012 |
| CVE-2007-5404 | Layton HelpBox 3.7.1 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote attackers to… | MEDIUM | 1.19% | Jan 9, 2008 |
| CVE-2007-5403 | Multiple cross-site scripting (XSS) vulnerabilities in Layton HelpBox 3.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1)… | LOW | 1.08% | Jan 9, 2008 |
| CVE-2007-5402 | Multiple SQL injection vulnerabilities in Layton HelpBox 3.7.1 allow (1) remote attackers to execute arbitrary SQL commands via the sys_request_id parameter to… | MEDIUM | 0.93% | Jan 9, 2008 |
| CVE-2007-5401 | Unrestricted file upload vulnerability in uploadrequest.asp in Layton HelpBox 3.7.1 allows remote authenticated users to upload and execute arbitrary ASP files… | MEDIUM | 1.11% | Jan 9, 2008 |
| CVE-2004-2551 | Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the sys_comment_id parameter in… | HIGH | 2.29% | Nov 21, 2005 |
Showing 1 to 11 of 11 CVEs