Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-0366

Опубликовано: 21 янв. 2010
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:bitscripts:bits_video_script:2.04:*:*:*:*:*:*:*
cpe:2.3:a:bitscripts:bits_video_script:2.05:gold_beta:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.03687
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
почти 4 года назад

Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

EPSS

Процентиль: 88%
0.03687
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-20