SphereServer BugTracker - SphereServer
View Issue Details
0001882SphereServerexecutable - genericpublic02-01-11 20:4112-01-14 17:04
Coruja 
XuN 
normalmajoralways
resolvedfixed 
 
 
09-09-2008
None
None
0001882: Exploit using timerf command
TIMERF doesn't check plevel to execute the function. An account with plevel 4 which can use TIMERF function can exploit plevel restriction and execute any function, like "TIMERF 1,ACCOUNT.PLEVEL 7"

So my suggestion is check is the account can use the function used on timerf, but only when it text the command on client (on scripts it must work without restrictions, since TIMERF functions run on many accounts with plevel 1)
No tags attached.
Issue History
02-01-11 20:41CorujaNew Issue
12-01-14 17:04XuNNote Added: 0001902
12-01-14 17:04XuNStatusnew => resolved
12-01-14 17:04XuNResolutionopen => fixed
12-01-14 17:04XuNAssigned To => XuN

Notes
(0001902)
XuN   
12-01-14 17:04   
Increase DefaultCommandLevel in sphere.ini