Artica Proxy Unauthenticated PHP Deserialization

Discussion in 'News Aggregator' started by Packet Storm, 28 Mar 2024.

  1. Packet Storm

    Packet Storm Guest

    A command injection vulnerability in Artica Proxy appliance versions 4.50 and 4.40 allows remote attackers to run arbitrary commands via an unauthenticated HTTP request. The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the www-data user.

    Continue reading...
     

Share This Page

Loading...