PT-2021-17994 · Magpierss · Magpierss

Bl4Ckh4Ck5

·

Published

2021-04-02

·

Updated

2022-12-13

·

CVE-2021-28940

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: MagpieRSS version 0.72
Description: The issue arises from an incorrectly escaped exec command in the /extlib/Snoopy.class.inc file. This allows an attacker to add an extra command to the curl binary, creating a problem on the /scripts/magpie debug.php and /scripts/magpie simple.php pages. By sending a specific https URL in the RSS URL field, an attacker can execute arbitrary commands.
Recommendations: For MagpieRSS version 0.72, consider disabling the exec command in the /extlib/Snoopy.class.inc file as a temporary workaround until a patch is available. Restrict access to the /scripts/magpie debug.php and /scripts/magpie simple.php pages to minimize the risk of exploitation. Avoid using the RSS URL field with untrusted input until the issue is resolved.

Exploit

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2021-28940

Affected Products

Magpierss