Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/24139
http://www.webhostautomation.com/webhost-301
http://www.vupen.com/english/advisories/2006/0203
http://www.securityfocus.com/bid/16234
http://www.securityfocus.com/archive/1/421791/100/0/threaded