EIP-2026-110890

PRE-CVE

PHP-Nuke NSN Script Depository 1.0.0 - Remote Source Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110890. PoCs published by KiNgOfThEwOrLd.

AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in PHP-Nuke NSN Script Depository module to disclose arbitrary file contents. The PoC generates an HTML form that submits a malicious path to the vulnerable module, allowing retrieval of sensitive files like configuration files containing database credentials.

Description

PHP-Nuke NSN Script Depository 1.0.0 - Remote Source Disclosure

Exploits (1)

exploitdb WORKING POC VERIFIED
by KiNgOfThEwOrLd · textwebappsphp
https://www.exploit-db.com/exploits/4667

This exploit leverages a directory traversal vulnerability in PHP-Nuke NSN Script Depository module to disclose arbitrary file contents. The PoC generates an HTML form that submits a malicious path to the vulnerable module, allowing retrieval of sensitive files like configuration files containing database credentials.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: PHP-Nuke NSN Script Depository module <= 1.0.0
No auth needed
Prerequisites: Target must have PHP-Nuke NSN Script Depository module <= 1.0.0 installed · Module must be accessible at the default path
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026