VULNERABILITY INTELLIGENCE
CVE-2010-0366
CVSS score6.8 MEDIUM
EPSS probability3.54%
CISA KEVNot currently listed
Published2010-01-21
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Description
Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
Weakness classification
- CWE-20: Improper Input Validation
Primary references
- cve@mitre.org
- cve@mitre.org — Vendor Advisory
- cve@mitre.org — Exploit
- cve@mitre.org
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Exploit
- af854a3a-2127-422b-91ae-364da2661108