CVE-2009-3647
YABSoft Mega File Hosting Script 1.2 - Cross-Site Scripting via emaullinks.php moudi Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3647. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Mega File Hosting Script 1.2 by injecting a script tag into the 'moudi' parameter of emaillinks.php, which executes arbitrary JavaScript in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in emaullinks.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the moudi parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in Mega File Hosting Script 1.2 by injecting a script tag into the 'moudi' parameter of emaillinks.php, which executes arbitrary JavaScript in the context of the affected site.