rbot 0.9.14 - '!react' Unauthorized Access

EDB-ID:

33935

CVE:

N/A


Author:

nks

Type:

remote


Platform:

Windows

Date:

2010-02-24


source: https://www.securityfocus.com/bid/39915/info

Rbot is prone to an unauthorized-access vulnerability because it fails to adequately sanitize user supplied data.

An attacker can exploit this vulnerability to gain administrative rights to the rbot application. This will allow a remote attacker to execute Ruby code within the context of the affected application; other attacks may be possible.

rbot 0.9.14 is vulnerable; other versions may also be affected. 

<attacker> !react to /attacker:.*/ with cmd:whoami