Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f4hx-rjjx-8grw

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.

index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.

EPSS

Процентиль: 90%
0.05244
Низкий

Связанные уязвимости

nvd
больше 20 лет назад

index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.

EPSS

Процентиль: 90%
0.05244
Низкий