rbot 0.9.14 - '!react' Unauthorized Access



EKU-ID: 38711 CVE: OSVDB-ID:
Author: nks Published: 2010-02-24 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/39915/info

Rbot is prone to an unauthorized-access vulnerability because it fails to adequately sanitize user supplied data.

An attacker can exploit this vulnerability to gain administrative rights to the rbot application. This will allow a remote attacker to execute Ruby code within the context of the affected application; other attacks may be possible.

rbot 0.9.14 is vulnerable; other versions may also be affected.

<attacker> !react to /attacker:.*/ with cmd:whoami