Ruslan Communications <Body>Builder SQL Injection Vulnerability
BID:5008
Info
Ruslan Communications <Body>Builder SQL Injection Vulnerability
| Bugtraq ID: | 5008 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0951 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Reported by Alexander Korchagin <[email protected]>. |
| Vulnerable: |
Ruslan Communications Builder |
| Not Vulnerable: | |
Discussion
Ruslan Communications Builder SQL Injection Vulnerability
Ruslan Communications <Body>Builder is a tool designed to assist a user in creating a website. It allows for remote administration through a web interface, and is implemented in Java.
Reportedly, user input supplied as the login password is not adequately filtered. A malicious user may include special characters in the supplied password and modify the SQL query used to validate the user. Access to the administrative interface is possible.
Ruslan Communications <Body>Builder is a tool designed to assist a user in creating a website. It allows for remote administration through a web interface, and is implemented in Java.
Reportedly, user input supplied as the login password is not adequately filtered. A malicious user may include special characters in the supplied password and modify the SQL query used to validate the user. Access to the administrative interface is possible.
Exploit / POC
Ruslan Communications Builder SQL Injection Vulnerability
Alexander Korchagin <[email protected]> has provided the following string, which could be used for authentication:
Use login='-- and pass='--
Alexander Korchagin <[email protected]> has provided the following string, which could be used for authentication:
Use login='-- and pass='--
Solution / Fix
Ruslan Communications Builder SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Ruslan Communications Builder SQL Injection Vulnerability
References:
References:
- Builder Homepage (Ruslan Communications)