Hi
Is there anything that is being done about this? I can find no forum posts or any info at all in here.
Would be interested to know whether the plan of action for this?
Thanks,
'); document.write(''); var yuipath = 'clientscript/yui'; var yuicombopath = ''; var remoteyui = false; } else // Load Rest of YUI remotely (where possible) { var yuipath = 'https://ajax.googleapis.com/ajax/libs/yui/2.9.0/build'; var yuicombopath = ''; var remoteyui = true; if (!yuicombopath) { document.write(''); } } var SESSIONURL = ""; var SECURITYTOKEN = "guest"; var IMGDIR_MISC = "warmane/misc"; var IMGDIR_BUTTON = "warmane/buttons"; var vb_disable_ajax = parseInt("0", 10); var SIMPLEVERSION = "422"; var BBURL = "https://forum.warmane.com"; var LOGGEDIN = 0 > 0 ? true : false; var THIS_SCRIPT = "showthread"; var RELPATH = "showthread.php?goto=nextoldest&t=468241"; var PATHS = { forum : "", cms : "", blog : "" }; var AJAXBASEURL = "https://forum.warmane.com/"; var CoTTooltips = { rename: true, icons: false, iconsize: 15, qualitycolor: true, overridecolor: { spells: '#839309', items: '', npcs: '#fff', objects: '#fff', quests: '#ffb100', achievements: '#fff' } }; // -->
Hi
Is there anything that is being done about this? I can find no forum posts or any info at all in here.
Would be interested to know whether the plan of action for this?
Thanks,
1) This RCE allows the server owner to execute code on the player's machine. It does NOT allow other players to execute code on your machine.
2) Even though this patcher was just released, this RCE was discovered years ago.
3) I think Warmane has used this RCE for a long time. For example, it is currently used to remotely patch the client to implement the Onyxia realm, and (probably) for anti-cheating purposes. If you patch your executable, you won't be able to play here.