Explore Vulnerabilities SQL Injection Cross-Site Scripting (XSS) Buffer Overflow Denial of Service Remote Code Execution Remote File Include Directory Traversal HTML Injection Stack Overflow Authentication Bypass
by: Gjoko 'LiquidWorm' Krstic, Zero Science Lab vendor: Tugux Studios Show More Tugux CMS 1.2 Multiple Remote Vulnerabilities The application suffers from multiple issues including: reflected and stored xss, sql Injection, local file inclusion, url redirection. Vulnerable parameters include: 'name', 'comment', 'nid', 'submit1', 'email', 'topic_id'. 8.8 CVSS HIGH Reflected and stored XSS, SQL Injection, Local File Inclusion, URL Redirection 79, 89, 94, 601 CWE Product Name Tugux CMS Platforms Tested Microsoft Windows XP Professional SP3 (EN), Apache 2.2.14 (Win32), PHP 5.3.1, MySQL 5.1.41 Affected Version From: 1.2 To: 1.2 2011