CVE-2009-3647 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 1.2% (pctl 67)
Patch early
A public exploit exists.
Description
Cross-site scripting (XSS) vulnerability in emaullinks.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the moudi parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 1.19% — more likely to be exploited than 67% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-10-09 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| yabsoft | mega file hosting script |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mega File Hosting Script 1.2 - 'emaillinks.php' Cross-Site Scripting | 2009-09-16 |
References
→ the Explorer · watch your stack · NVD