View Issue Details Jump to Notes ] Issue History ] Print ]
IDProjectCategoryView StatusDate SubmittedLast Update
0001882SphereServerexecutable - genericpublic02-01-11 20:4112-01-14 17:04
ReporterCoruja 
Assigned ToXuN 
PrioritynormalSeveritymajorReproducibilityalways
StatusresolvedResolutionfixed 
PlatformOSOS Version
Product Version 
Target VersionFixed in Version 
Summary0001882: Exploit using timerf command
DescriptionTIMERF doesn't check plevel to execute the function. An account with plevel 4 which can use TIMERF function can exploit plevel restriction and execute any function, like "TIMERF 1,ACCOUNT.PLEVEL 7"

So my suggestion is check is the account can use the function used on timerf, but only when it text the command on client (on scripts it must work without restrictions, since TIMERF functions run on many accounts with plevel 1)
TagsNo tags attached.
Nightly Version09-09-2008
Experimental FlagsNone
Option FlagsNone
Internal Build Number
Attached Files

- Relationships

-  Notes
(0001902)
XuN (developer)
12-01-14 17:04

Increase DefaultCommandLevel in sphere.ini

- Issue History
Date Modified Username Field Change
02-01-11 20:41 Coruja New Issue
12-01-14 17:04 XuN Note Added: 0001902
12-01-14 17:04 XuN Status new => resolved
12-01-14 17:04 XuN Resolution open => fixed
12-01-14 17:04 XuN Assigned To => XuN


Copyright © 2000 - 2010 MantisBT Group
Powered by Mantis Bugtracker