PT-2020-15027 · Artica · Artica Web Proxy

CVE-2020-17505

·

Published

2020-08-12

·

Updated

2023-01-24

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Artica Web Proxy version 4.30.000000
Description The issue allows an authenticated remote attacker to inject commands via the service-cmds parameter in "cyrus.php". These commands are executed with root privileges through the service cmds peform function.
Recommendations For Artica Web Proxy version 4.30.000000, consider restricting access to the "cyrus.php" file to prevent command injection until a patch is available. As a temporary workaround, avoid using the service-cmds parameter in the affected API endpoint.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-17505

Affected Products

Artica Web Proxy