The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server.
| Software | From | Fixed in |
|---|---|---|
| sean_macguire / big_brother | 1.3 | 1.3.x |
| sean_macguire / big_brother | 1.4h1 | 1.4h1.x |
| sean_macguire / big_brother | 1.4 | 1.4.x |
| sean_macguire / big_brother | 1.0 | 1.0.x |
| sean_macguire / big_brother | 1.4g | 1.4g.x |
| sean_macguire / big_brother | 1.2 | 1.2.x |
| sean_macguire / big_brother | 1.09d | 1.09d.x |
| sean_macguire / big_brother | 1.09b | 1.09b.x |
| sean_macguire / big_brother | 1.09c | 1.09c.x |
| sean_macguire / big_brother | 1.4h | 1.4h.x |
| sean_macguire / big_brother | 1.3b | 1.3b.x |
| sean_macguire / big_brother | 1.1 | 1.1.x |