CVE

Id
12802  
CVE No.
CVE-2005-1596  
Status
Candidate  
Description
index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.  
Phase
Assigned (20050516)  
Votes
None (candidate not yet proposed)  
Comments