Variable $username isn't properly sanitized before being used in a SQL
query. This can be used to bypass authentication or make any SQL query by
injecting arbitrary SQL code.
All applications based on "SZUserMgnt class" are vulnerable.
Condition: gpc_magic_quotes - off
--------------Exploit----------------------
Available at: http://evuln.com/vulns/53/exploit.html
--------------Solution---------------------
No Patch available.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.