Security Advisory

CVE-2005-1596

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2005-05-16 04:00:00
Last updated 2024-08-07 21:59:22
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.