Skip to content

Commit 0c8f5e9

Browse files
committed
Add @firefart's feedback
1 parent b0b979c commit 0c8f5e9

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

modules/exploits/linux/antivirus/escan_password_exec.rb

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -90,7 +90,7 @@ def cmd_exec(session, cmd)
9090
# Escalating privileges here because runasroot only can't be executed by
9191
# mwconf uid (196).
9292
def on_new_session(session)
93-
cmd_exec(session, "#{datastore['RUNASROOT']} /bin/sh")
93+
cmd_exec(session, "#{datastore['RUNASROOT'].shellescape} /bin/sh")
9494
super
9595
end
9696

@@ -101,7 +101,7 @@ def primer
101101

102102
def on_request_uri(cli, request)
103103
print_status("Request: #{request.uri}")
104-
if request.uri =~ /#{get_resource}/
104+
if request.uri =~ /#{Regexp.escape(get_resource)}/
105105
print_status("Sending payload...")
106106
send_response(cli, @pl)
107107
end

0 commit comments

Comments
 (0)