Vulnerabilities > Bitscripts
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2010-01-21 | CVE-2010-0367 | Code Injection vulnerability in Bitscripts Bits Video Script 2.04/2.05 Multiple PHP remote file inclusion vulnerabilities in BitScripts Bits Video Script 2.05 Gold Beta, and possibly 2.04, allow remote attackers to execute arbitrary PHP code via a URL in the rowptem[template] parameter to (1) showcasesearch.php and (2) showcase2search.php. | 7.5 |
2010-01-21 | CVE-2010-0366 | Improper Input Validation vulnerability in Bitscripts Bits Video Script 2.04/2.05 Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory. | 6.8 |
2010-01-21 | CVE-2010-0365 | Cross-Site Scripting vulnerability in Bitscripts Bits Video Script 2.04/2.05 Cross-site scripting (XSS) vulnerability in search.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allows remote attackers to inject arbitrary web script or HTML via the order parameter. | 4.3 |