SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an authenticated user to execute arbitrary Python commands on the underlying operating system.
{
"binaries": [
{
"binary_name": "sabnzbdplus",
"binary_version": "0.7.20+dfsg-1"
},
{
"binary_name": "sabnzbdplus-theme-classic",
"binary_version": "0.7.20+dfsg-1"
},
{
"binary_name": "sabnzbdplus-theme-iphone",
"binary_version": "0.7.20+dfsg-1"
},
{
"binary_name": "sabnzbdplus-theme-mobile",
"binary_version": "0.7.20+dfsg-1"
},
{
"binary_name": "sabnzbdplus-theme-plush",
"binary_version": "0.7.20+dfsg-1"
},
{
"binary_name": "sabnzbdplus-theme-smpl",
"binary_version": "0.7.20+dfsg-1"
}
]
}