ValveSoftware / source-sdk-2013

The 2013 edition of the Source SDK
https://developer.valvesoftware.com/wiki/SDK2013_GettingStarted
Other
3.69k stars 1.99k forks source link

NET_StringCmd exploit #567

Open usernameunavalible0 opened 11 months ago

usernameunavalible0 commented 11 months ago

Power tripping server admins can exploit NET_StringCmd/ProcessStringCmd in the engine to execute commands on the game client such as retry, unbindall, etc... This appears to be patched in other source games tf2/css/csgo/dota2 but not in sdk2013. This is very bad please patch Valve!