CVE-2009-4266
YABSoft AIH Script <2.3 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in search.php in YABSoft Advanced Image Hosting (AIH) Script 2.2, and possibly 2.3, allows remote attackers to inject arbitrary web script or HTML via the text parameter.
Exploits (1)
Scores
EPSS
0.0072
EPSS Percentile
72.3%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
yabsoft/advanced_image_hosting_script
yabsoft/advanced_image_hosting_script
n/a/n/a
Timeline
Published
Dec 10, 2009
Tracked Since
Feb 18, 2026