HIGH
index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter
Published May 16, 2005
10.0
HIGHCVSS 2.0
EPSS 6.95%
Description
Affected products
Remediation
References (7)
Change history (0)
No recorded changes yet.