rbot 0.9.14 - '!react' Unauthorized Access
Author: nks
type: remote
platform: windows
port:
date_added: 2010-02-24
date_updated: 2014-07-01
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/39915/info
Rbot is prone to an unauthorized-access vulnerability because it fails to adequately sanitize user supplied data.
An attacker can exploit this vulnerability to gain administrative rights to the rbot application. This will allow a remote attacker to execute Ruby code within the context of the affected application; other attacks may be possible.
rbot 0.9.14 is vulnerable; other versions may also be affected.
<attacker> !react to /attacker:.*/ with cmd:whoami