PT-2020-15027 · Artica · Artica Web Proxy

Published

2020-08-12

·

Updated

2023-01-24

·

CVE-2020-17505

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Artica Web Proxy version 4.30.000000
Description The issue allows an authenticated remote attacker to inject commands via the service-cmds parameter in "cyrus.php". These commands are executed with root privileges through the service cmds peform function.
Recommendations For Artica Web Proxy version 4.30.000000, consider restricting access to the "cyrus.php" file to prevent command injection until a patch is available. As a temporary workaround, avoid using the service-cmds parameter in the affected API endpoint.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-17505

Affected Products

Artica Web Proxy