{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-20T11:56:43.222","vulnerabilities":[{"cve":{"id":"CVE-2009-3647","sourceIdentifier":"cve@mitre.org","published":"2009-10-09T14:30:00.407","lastModified":"2026-06-16T23:12:05.390","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in emaullinks.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the moudi parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."},{"lang":"es","value":"Una vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en emaullinks.php en YABSoft Mega File Hosting Script (alias MFH o MFHS) v1.2 permite a atacantes remotos inyectar HTML o scripts web a través del parámetro moudi. NOTA: la procedencia de esta información es desconocida, los detalles son obtenidos exclusivamente de la información de terceros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:yabsoft:mega_file_hosting_script:1.2:*:*:*:*:*:*:*","matchCriteriaId":"3A06E0F8-5235-4C71-9473-C75051AF5C00"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/36413","source":"cve@mitre.org","tags":["Exploit"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53642","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/36413","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53642","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}