DerbyNet version 9.0 suffers from a cross site scripting vulnerability in photo-thumbs.php. Continue reading...