Security Advisory

CVE-2010-2314

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2010-06-17 16:00:00
Last updated 2024-09-16 23:22:07
Assigner mitre
State PUBLISHED

Description

PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucleus, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PLUGINS parameter. NOTE: some of these details are obtained from third party information.