VULNERABILITY INTELLIGENCE

CVE-2010-0366

CVSS score6.8 MEDIUM
EPSS probability3.54%
CISA KEVNot currently listed
Published2010-01-21
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:P/I:P/A:P

Description

Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

Weakness classification

  • CWE-20: Improper Input Validation

Primary references