vendor:
Sickbeard
by:
bdrake
7.5
CVSS
HIGH
Remote Command Injection
78
CWE
Product Name: Sickbeard
Affected Version From: alpha (master) -- git : 31ceaf1b5cab1884a280fe3f4609bdc3b1fb3121
Affected Version To: alpha (master) -- git : 31ceaf1b5cab1884a280fe3f4609bdc3b1fb3121
Patch Exists: YES
Related CWE: NA
CPE: a:sickbeard:sickbeard
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Fedora 32
2020
Sickbeard 0.1 – Remote Command Injection
Sickbeard 0.1 is vulnerable to Remote Command Injection. An attacker can exploit this vulnerability by setting malicious commands in the 'Extra Scripts' field of the Sickbeard configuration page. The malicious commands can be executed when a local video is processed. This vulnerability affects Sickbeard version alpha (master) -- git : 31ceaf1b5cab1884a280fe3f4609bdc3b1fb3121 running on Fedora 32.
Mitigation:
Disable the 'Extra Scripts' field in the Sickbeard configuration page. Ensure that the Sickbeard version is up to date.