4.3
CVSSv2

CVE-2009-4266

Published: 10/12/2009 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in search.php in YABSoft Advanced Image Hosting (AIH) Script 2.2, and possibly 2.3, allows remote malicious users to inject arbitrary web script or HTML via the text parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

yabsoft advanced image hosting script 2.2

yabsoft advanced image hosting script 2.3

Exploits

UBBCentral: wwwubbcentralcom/ UBBthreads is prone to multiple file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data Exploiting these issues may allow an attacker to compromise the application and the computer; other attacks are also possible UBBthreads 7542 is vulnerable; other versions may also ...