← Advisories

Tugux CMS 1.2 Multiple Remote Vulnerabilities

High
Advisory ID
ZSL-2011-5014
Release Date
22 May 2011
Vendor
Tugux Studios - http://www.tugux.com
Affected Version
1.2
CVE
N/A
Tested On
Microsoft Windows XP Professional SP3 (EN), Apache 2.2.14 (Win32), PHP 5.3.1, MySQL 5.1.41
Summary

Tugux CMS is a free, open-source content Management system (CMS) and application that powers the entire web.

Description

The application suffers from multiple issues including: reflected and stored xss, sql Injection, local file inclusion, url redirection. Vulnerable parameters include: 'name', 'comment', 'nid', 'submit1', 'email', 'topic_id'.

Proof of Concept
Disclosure Timeline
02.04.2011Vulnerabilities discovered.
08.04.2011Vendor contact.
17.05.2011Vendor replies asking more details.
17.05.2011Sent vendor report file, asking verification.
20.05.2011No response from vendor.
21.05.2011Sent another e-mail asking for any info.
21.05.2011No reply from vendor.
22.05.2011Public advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
22.05.2011Initial release
23.05.2011Added reference [2], [3], [4] and [5]
24.05.2011Added reference [6], [7] and [8]
13.06.2011Added reference [9], [10], [11] and [12]