10
CVSSv2

CVE-2002-0951

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

SQL injection vulnerability in Ruslan <Body>Builder allows remote malicious users to gain administrative privileges via a "'--" sequence in the username and password.

Vulnerable Product Search on Vulmon Subscribe to Product

ruslan communications body builder

Exploits

source: wwwsecurityfocuscom/bid/5008/info Ruslan Communications &lt;Body&gt;Builder is a tool designed to assist a user in creating a website It allows for remote administration through a web interface, and is implemented in Java Reportedly, user input supplied as the login password is not adequately filtered A malicious user may incl ...