PT-2021-17994 · Magpierss · Magpierss
Bl4Ckh4Ck5
·
Published
2021-04-02
·
Updated
2022-12-13
·
CVE-2021-28940
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
MagpieRSS version 0.72
Description:
The issue arises from an incorrectly escaped exec command in the /extlib/Snoopy.class.inc file. This allows an attacker to add an extra command to the curl binary, creating a problem on the /scripts/magpie debug.php and /scripts/magpie simple.php pages. By sending a specific https URL in the RSS URL field, an attacker can execute arbitrary commands.
Recommendations:
For MagpieRSS version 0.72, consider disabling the
exec command in the /extlib/Snoopy.class.inc file as a temporary workaround until a patch is available. Restrict access to the /scripts/magpie debug.php and /scripts/magpie simple.php pages to minimize the risk of exploitation. Avoid using the RSS URL field with untrusted input until the issue is resolved.Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Magpierss