Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown

CVE-2020-13159

Disclosure Date: June 22, 2020 (last updated February 21, 2025)
Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overlap CVE-2020-10818.
Attacker Value
Unknown

CVE-2020-10818

Disclosure Date: March 22, 2020 (last updated February 21, 2025)
Artica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the hostname" field.
Attacker Value
Unknown

CVE-2019-7300

Disclosure Date: February 01, 2019 (last updated November 27, 2024)
Artica Proxy 3.06.200056 allows remote attackers to execute arbitrary commands as root by reading the ressources/settings.inc ldap_admin and ldap_password fields, using these credentials at logon.php, and then entering the commands in the admin.index.php command-line field.
0
Attacker Value
Unknown

CVE-2017-17055

Disclosure Date: December 07, 2017 (last updated November 26, 2024)
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php.
0