A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.
References
Link | Resource |
---|---|
https://medium.com/@rootless724/artica-proxy-4-30-cyrus-events-php-rce-3aa2a868c695 | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-05-05 04:15
Updated : 2022-05-13 08:01
NVD link : CVE-2021-41739
Mitre link : CVE-2021-41739
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
artica-proxy
- artica_proxy