Yabsoft develops a narrow line of web-based file-hosting and image-hosting application products, each of which presents a persistent attack surface for server-side injection flaws. The vendor's vulnerability disclosures concentrate on input-handling weaknesses—SQL injection, cross-site scripting, and code injection—that are characteristic of server-side web applications built without defense-in-depth input validation. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yabsoft over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6039HIGH SQL injection vulnerability in view_comments.php in YABSoft Advanced Image Hosting (AIH) Script, possibly 2.3, allows remote attackers to execute arbitrary SQL commands via the gal | Nov 26, 2012 | 7.5 | 32 | NO | YES |
CVE-2009-0966HIGH PHP remote file inclusion vulnerability in cross.php in YABSoft Mega File Hosting 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter. NOTE: t | Mar 19, 2009 | 7.5 | 29 | NO | YES |
CVE-2009-1032HIGH SQL injection vulnerability in gallery_list.php in YABSoft Advanced Image Hosting (AIH) Script 2.3 allows remote attackers to execute arbitrary SQL commands via the gal parameter. | Mar 20, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-2521MEDIUM SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authenticated users to execute arbitrary SQL commands via the fid | Jun 3, 2008 | 6.5 | 28 | NO | YES |
CVE-2008-2536HIGH SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the t parameter. | Jun 3, 2008 | 7.5 | 28 | NO | YES |
CVE-2009-4266MEDIUM Cross-site scripting (XSS) vulnerability in search.php in YABSoft Advanced Image Hosting (AIH) Script 2.2, and possibly 2.3, allows remote attackers to inject arbitrary web script | Dec 10, 2009 | 4.3 | 21 | NO | YES |
CVE-2009-3647MEDIUM Cross-site scripting (XSS) vulnerability in emaullinks.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote attackers to inject arbitrary web script or HTML | Oct 9, 2009 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yabsoft.
Media articles that mention a CVE ID that affects a product developed by Yabsoft — matched by CVE ID, not by vendor name.