Tugux CMS Multiple Security Vulnerabilities
BID:47939
Info
Tugux CMS Multiple Security Vulnerabilities
| Bugtraq ID: | 47939 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2011 12:00AM |
| Updated: | May 22 2011 12:00AM |
| Credit: | Gjoko Krstic |
| Vulnerable: |
Tugux Studios Tugux CMS 1.2 |
| Not Vulnerable: | |
Discussion
Tugux CMS Multiple Security Vulnerabilities
Tugux CMS is prone to multiple security vulnerabilities that inlcudes SQL-injection, cross-site scripting, HTML-injection, local file-include and remote file-include.
Exploiting these issues may allow a remote attacker to obtain sensitive information or to execute arbitrary script code in the context of the webserver process, allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user and allows an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Tugux CMS 1.2 is vulnerable; other versions may also be affected.
Tugux CMS is prone to multiple security vulnerabilities that inlcudes SQL-injection, cross-site scripting, HTML-injection, local file-include and remote file-include.
Exploiting these issues may allow a remote attacker to obtain sensitive information or to execute arbitrary script code in the context of the webserver process, allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user and allows an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Tugux CMS 1.2 is vulnerable; other versions may also be affected.
Exploit / POC
Tugux CMS Multiple Security Vulnerabilities
Attackers can exploit these issues through a browser.
The following example URIs are available:
Attackers can exploit these issues through a browser.
The following example URIs are available:
References
Tugux CMS Multiple Security Vulnerabilities
References:
References:
- Tugux CMS 1.2 Multiple Remote Vulnerabilities (Zero Science Lab)
- Vendor Homepage (Tugux Studios)