CVE-2002-0951
Ruslan <Body>Builder - SQL Injection via Username and Password Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-0951. PoCs published by Alexander Korchagin.
AI-analyzed exploit summary This exploit leverages SQL injection in Ruslan Communications BodyBuilder's login mechanism by injecting special characters into the password field to bypass authentication. The provided credentials ('-- as both login and password) comment out the rest of the SQL query, allowing unauthorized access.
Description
SQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a "'--" sequence in the username and password.
Exploits (1)
This exploit leverages SQL injection in Ruslan Communications BodyBuilder's login mechanism by injecting special characters into the password field to bypass authentication. The provided credentials ('-- as both login and password) comment out the rest of the SQL query, allowing unauthorized access.