CVE-2010-5040
Nucleus NP_Gallery <0.94 - RCE
Title source: llmDescription
PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary PHP code via a URL in the DIR_NUCLEUS parameter. NOTE: some of these details are obtained from third party information.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by AntiSecurity · textwebappsphp
https://www.exploit-db.com/exploits/12787
Scores
EPSS
0.0197
EPSS Percentile
83.3%
Classification
CWE
CWE-94
Status
draft
Affected Products (1)
john_bradshaw/np_gallery_plugin
Timeline
Published
Nov 02, 2011
Tracked Since
Feb 18, 2026