We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent b0b979c commit 0c8f5e9Copy full SHA for 0c8f5e9
modules/exploits/linux/antivirus/escan_password_exec.rb
@@ -90,7 +90,7 @@ def cmd_exec(session, cmd)
90
# Escalating privileges here because runasroot only can't be executed by
91
# mwconf uid (196).
92
def on_new_session(session)
93
- cmd_exec(session, "#{datastore['RUNASROOT']} /bin/sh")
+ cmd_exec(session, "#{datastore['RUNASROOT'].shellescape} /bin/sh")
94
super
95
end
96
@@ -101,7 +101,7 @@ def primer
101
102
def on_request_uri(cli, request)
103
print_status("Request: #{request.uri}")
104
- if request.uri =~ /#{get_resource}/
+ if request.uri =~ /#{Regexp.escape(get_resource)}/
105
print_status("Sending payload...")
106
send_response(cli, @pl)
107
0 commit comments