First published: Thu Jun 17 2010(Updated: )
PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucleus, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PLUGINS parameter. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
=0.8 | ||
=0.9 | ||
NucleusCMS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2314 is considered a critical vulnerability due to its remote file inclusion nature, which allows attackers to execute arbitrary PHP code.
To mitigate CVE-2010-2314, disable register_globals in your PHP configuration and upgrade to a secure version of the NP_Twitter Plugin.
CVE-2010-2314 affects NP_Twitter Plugin versions 0.8 and 0.9.
Systems using Nucleus CMS with NP_Twitter Plugin versions 0.8 or 0.9 and have register_globals enabled are vulnerable to CVE-2010-2314.
Yes, CVE-2010-2314 can lead to data breaches, as attackers could execute arbitrary code to manipulate the server and access sensitive information.