9
CVSSv2

CVE-2020-17505

Published: 12/08/2020 Updated: 24/01/2023
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 802
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Artica Web Proxy 4.30.000000 allows an authenticated remote malicious user to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

articatech web proxy 4.30.000000

Exploits

This Metasploit module exploits an authenticated command injection vulnerability in Artica Proxy, combined with an authentication bypass discovered on the same version, it is possible to trigger the vulnerability without knowing the credentials The application runs in a virtual appliance and successful exploitation of this vulnerability yields rem ...