6.8
CVSSv2

CVE-2010-2314

Published: 17/06/2010 Updated: 18/06/2010
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucleus, when register_globals is enabled, allows remote malicious users to execute arbitrary PHP code via a URL in the DIR_PLUGINS parameter. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

edmondhui.homeip np_twitter 0.9

edmondhui.homeip np_twitter 0.8

Exploits

============================================================================================================= [o] Nucleus Plugin Twitter Remote File Inclusion Vulnerability Software : NP_Twitter version 08 Download : edmondhuihomeipnet/nudn?file=2/NP_Twitter_v0_8zip Author : AntiSecurity [ NoGe Vrs-hCk OoN_Bo ...