CVE-2004-2551

Layton HelpBox 3.0.1 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-2551. PoCs published by Noam Rathaus.

AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in HelpBox 3.0.1, specifically in the 'editcommentenduser.asp' script, due to improper sanitization of user-supplied input. It outlines potential impacts such as unauthorized data access or manipulation.

Description

Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the sys_comment_id parameter in editcommentenduser.asp, (2) the sys_suspend_id parameter in editsuspensionuser.asp, (3) the table parameter in export_data.asp, (4) the sys_analgroup parameter in manageanalgrouppreference.asp, (5) the sys_asset_id parameter in quickinfoassetrequests.asp, (6) the sys_eusername parameter in quickinfoenduserrequests.asp, and the sys_request_id parameter in (7) requestauditlog.asp, (8) requestcommentsenduser.asp, (9) selectrequestapplytemplate.asp, and (10) selectrequestlink.asp, resulting in an ability to create a new HelpBox user account and read, modify, or delete data from the backend database.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Noam Rathaus · textwebappsphp
https://www.exploit-db.com/exploits/24303

The provided text describes SQL injection vulnerabilities in HelpBox 3.0.1, specifically in the 'editcommentenduser.asp' script, due to improper sanitization of user-supplied input. It outlines potential impacts such as unauthorized data access or manipulation.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: HelpBox 3.0.1
No auth needed
Prerequisites: Access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (15)

Core 15
Core References
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/8177
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/8172
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/8170
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/8174
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/8171
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/8173
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/8178
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16772
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12118
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/8179
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16774
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/8175
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10776
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/8176

Scores

EPSS 0.0229
EPSS Percentile 80.9%

Details

Status published
Products (1)
layton_technology/helpbox 3.0.1
Published Dec 31, 2004
Tracked Since Feb 18, 2026