1 results (0.003 seconds)

CVSS: 10.0EPSS: 5%CPEs: 1EXPL: 2

16 May 2005 — index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter. • http://secunia.com/advisories/15257 •