SABnzbd Exposure Scanner
This scanner probes for accessible SABnzbd installation wizard endpoints, allowing attackers to view or modify application configurations without authentication.
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
16 days 1 hour
Scan only one
URL
Toolbox
SABnzbd is a popular open-source binary newsreader for Usenet, used by individuals and organizations to automate downloading of binary content. It provides a web interface for managing downloads, scheduling, and integrations with third-party apps. Tech-savvy users and network administrators rely on it for efficient Usenet file handling.
The vulnerability involves exposure of the SABnzbd installation wizard page, which should only be accessible during initial setup. If left accessible after configuration, it allows unauthorized users to access and modify application settings, leading to potential misconfigurations or security breaches.
Technically, the scanner checks for the presence of the installation wizard endpoint, typically at paths like /wizard or /setup. If this page is accessible without authentication, it indicates a misconfiguration where the wizard was not disabled post-installation.
Exploitation could allow an attacker to change critical settings, such as download directories, API keys, or network configurations, potentially leading to data theft, service disruption, or further compromise of the host system.