CVE-2009-4266

YABSoft AIH Script <2.3 - XSS

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in search.php in YABSoft Advanced Image Hosting (AIH) Script 2.2, and possibly 2.3, allows remote attackers to inject arbitrary web script or HTML via the text parameter.

Exploits (1)

exploitdb WORKING POC
by R3VAN_BASTARD · textwebappsphp
https://www.exploit-db.com/exploits/10305

References (3)

Core 3
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/10336
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/54582
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34366

Scores

EPSS 0.0072
EPSS Percentile 72.6%

Details

CWE
CWE-79
Status published
Products (2)
yabsoft/advanced_image_hosting_script 2.2
yabsoft/advanced_image_hosting_script 2.3
Published Dec 10, 2009
Tracked Since Feb 18, 2026