MagpieRSS version 0.72 suffers from command injection and server-side request forgery vulnerabilities.