Juice 51ede1097d
admincmd.sma exploits fix (#822)
* [admincmd.sma] Fix typo in isCommandArgSafe

'

* [admincmd.sma] Update amx_cvar command handler

- Fix exploiting of "mapchangecfgfile" cvar to execute potentially dangerous console commands
- Add newline delimiter check and restrict for ****cfgfile cvars values

* Restrict having ".." character sequence in amx_map command argument

Fixes exploit on Windows servers that allows executing potentially dangerous console commands

* Do not allow admins to change cvars with FCVAR_SPONLY flag when not in singleplayer via amx_cvar

1. Make amx_cvar command obey FCVAR_SPONLY flag.
2. Fix exploiting of amx_nextmap cvar value which is used in nextmap plugin.
2020-05-29 01:10:38 +02:00
..
2015-03-29 20:01:25 +02:00
2018-08-30 18:41:49 +02:00
2005-08-24 06:13:55 +00:00
2017-09-30 20:23:12 +02:00
2018-08-30 18:41:49 +02:00
2018-08-30 18:41:49 +02:00
2020-05-29 01:10:38 +02:00
2020-05-29 01:04:16 +02:00
2015-02-01 19:25:36 +01:00
2015-05-17 19:50:42 +03:00
2005-07-30 00:31:42 +00:00
2014-05-18 20:37:44 -05:00
2015-07-11 00:39:34 +03:00
2015-07-11 00:39:34 +03:00
2015-07-11 00:39:34 +03:00
2015-02-23 02:21:20 +05:00
2015-02-01 19:25:36 +01:00
2015-02-01 19:25:36 +01:00
2015-02-01 21:45:16 +01:00
2015-02-01 19:25:36 +01:00