SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-3159
http://www.securityfocus.com/bid/14489