S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2017-5982 Scanner

CVE-2017-5982 scanner - Directory Traversal vulnerability in Chorus2 add-on for Kodi

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
3.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-5982
7.5
CVSS

Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 5, 2026View on NVD →
Detail

Chorus2 is a popular add-on for Kodi, a free and open-source media player software used for streaming digital content such as films, TV shows, and music. The Chorus2 add-on is specifically used for managing and organizing media files, allowing users to browse their collections in a user-friendly interface. It also provides features like metadata editing and artwork management, making it a handy tool for media enthusiasts.

However, the Chorus2 add-on was found to have a critical vulnerability, known as CVE-2017-5982. This vulnerability allows remote attackers to gain unauthorized access to a user's system by exploiting a directory traversal flaw in the software's image path. By encoding a "dot dot slash" sequence (%2E%2E%252e) into the image path, attackers can break out of the intended directory and access arbitrary files on the system, including sensitive files like /etc/passwd (which contains user account information).

Exploiting this vulnerability can lead to a myriad of consequences, ranging from identity theft to system compromise. Attackers can use the information they access to conduct further attacks and gain even more sensitive data. It's a serious threat to user privacy and security, and needs to be addressed immediately.

At s4e.io, we take cybersecurity seriously. Our platform provides pro features that allow users to easily and quickly learn about vulnerabilities in their digital assets. By subscribing to our services, users can access real-time vulnerability alerts and get insights into how to best protect their systems against threats like CVE-2017-5982. Don't wait until it's too late, protect yourself today.

 

REFERENCES

Solution Advice

Thankfully, there are precautions that can be taken to protect against this vulnerability. Here are some quick bullet points to keep in mind:

  • Update to the latest version of Kodi and Chorus2 add-on, which may have patched this vulnerability.
  • Avoid clicking on suspicious links or downloading files from untrusted sources.
  • Regularly scan your system for malicious activity using reliable antivirus software.
  • Use secure passwords and enable two-factor authentication wherever possible.
  • Practice good cybersecurity hygiene, such as keeping your operating system and other software up to date.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.