=================================================================== Tugux CMS 1.2 Multiple vulnerability (BLIND sql & xss) =================================================================== Software: Tugux CMS Vendor: www.tugux.com Vuln Type: BLind SQL Injection Download link: http://www.tugux.com/uploads/47/tugux_cms.rar Author: eidelweiss contact: admin[at]eidelweiss[dot]info Home: www.eidelweiss.info References: http://eidelweiss-advisories.blogspot.com/2011/07/tugux-cms-12-multiple-vulnerability.html =================================================================== Vuln c0de on page_text.php ">'> then the site will direct you to http://server/latest.php?nid= and there you go.. xss will pop up p0c: http://server/comments.php or http://server/path/comments.php official site: http://www.tugux.com/comments.php Gratz: - YOGYACARDERLINK , DEVILZC0DE , etc - Nofia Fitri (unyu˛), whitehat, note, petimati, psycothic_girl, viska agasi (dudutzkuw), wenkhairu, etc (capek aja di ketik semua) ==================================================================== Nothing Impossible In This World Even Nobody`s Perfect Hacking is Art =================================================================== ==========================| -=[ E0F ]=- |==========================