peter bassill · operator
$ cve CVE-2010-0366 JSON

CVE-2010-0366 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 3.5% (pctl 89)

Patch early

A public exploit exists.

Description

Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS3.54% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2010-01-21
Last modified2026-06-16

Affected (1)

VendorProduct
bitscriptsbits video script

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD