Monte Ohrt

3 exploits Active since Sep 2018
CVE-2018-13982 WRITEUP HIGH WRITEUP
Smarty < 3.1.33 - Path Traversal via Trusted Resource Directory Bypass
Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files.
CVSS 7.5
CVE-2021-28940 WRITEUP CRITICAL WRITEUP
MagpieRSS 0.72 - OS Command Injection via RSS URL Parameter
Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command to the curl binary. This creates an issue on the /scripts/magpie_debug.php and /scripts/magpie_simple.php page that if you send a specific https url in the RSS URL field, you are able to execute arbitrary commands.
CVSS 9.8
CVE-2021-28941 WRITEUP MEDIUM WRITEUP
MagpieRSS 0.72 - Server-Side Request Forgery via Snoopy curl Request
Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a request to the /scripts/magpie_debug.php or /scripts/magpie_simple.php page, it's possible to request any internal page if you use a https request.
CVSS 5.3