Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with shell metacharacters in the title, which are substituted unescaped for $SPOTTITLE and passed to exec() when a user downloads the spot, running commands as the Spotweb PHP process.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 10 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with shell metacharacters in the title, which are substituted unescaped for $SPOTTITLE and passed to exec() when a user downloads the spot, running commands as the Spotweb PHP process. | |
| Title | Spotweb through 1.5.8 OS Command Injection via Spot Title in Runcommand Integration | |
| First Time appeared |
Spotweb Project
Spotweb Project spotweb |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:spotweb_project:spotweb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Spotweb Project
Spotweb Project spotweb |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-10T14:15:52.852Z
Reserved: 2026-10-10T14:06:53.765Z
Link: CVE-2026-108546
No data.
Status : Received
Published: 2026-10-10T15:16:57.573
Modified: 2026-10-10T15:16:57.573
Link: CVE-2026-108546
No data.
OpenCVE Enrichment
Updated: 2026-10-10T15:30:17Z
Weaknesses