SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an authenticated user to execute arbitrary Python commands on the underlying operating system.
{
"binaries": [
{
"binary_version": "0.7.20+dfsg-1",
"binary_name": "sabnzbdplus"
},
{
"binary_version": "0.7.20+dfsg-1",
"binary_name": "sabnzbdplus-theme-classic"
},
{
"binary_version": "0.7.20+dfsg-1",
"binary_name": "sabnzbdplus-theme-iphone"
},
{
"binary_version": "0.7.20+dfsg-1",
"binary_name": "sabnzbdplus-theme-mobile"
},
{
"binary_version": "0.7.20+dfsg-1",
"binary_name": "sabnzbdplus-theme-plush"
},
{
"binary_version": "0.7.20+dfsg-1",
"binary_name": "sabnzbdplus-theme-smpl"
}
]
}