CVE-2009-4681

phpDirectorySource 1.x - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in search.php in phpDirectorySource 1.x allows remote attackers to inject arbitrary web script or HTML via the st parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/9226

Scores

EPSS 0.0265
EPSS Percentile 85.6%

Classification

CWE
CWE-79
Status published

Affected Products (3)

phpdirectorysource/phpdirectorysource
phpdirectorysource/phpdirectorysource
n/a/n/a

Timeline

Published Mar 10, 2010
Tracked Since Feb 18, 2026