vendor:
Tugux CMS 1.0_final
by:
Aodrulez (Atul Alex Cherian)
7.5
CVSS
HIGH
SQLi, create_admin_parse.php
89, 522
CWE
Product Name: Tugux CMS 1.0_final
Affected Version From: 1.0_final
Affected Version To: 1.0_final
Patch Exists: NO
Related CWE: N/A
CPE: a:tuguxcms:tugux_cms:1.0_final
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 10.04
2011
Tugux CMS 1.0_final Multiple Vulnerabilities
Tugux CMS 1.0_final is vulnerable to multiple vulnerabilities, including SQL injection and an exploit in create_admin_parse.php which can be used to add Super Admin Accounts without any authentication. The exploit is written in Perl code.
Mitigation:
Ensure that all user input is properly sanitized and validated before being used in SQL queries. Ensure that authentication is required for all administrative functions.