Home/Product/articatech artica proxy
Product

articatech artica proxy

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-2054
all versions
The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subse
9.8CRITICAL
CVE-2024-2053
all versions
The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subse
7.5HIGH
CVE-2024-2056
all versions
Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In par
9.8CRITICAL
CVE-2024-2055
all versions
The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature i
9.8CRITICAL
CVE-2022-37153
all versions
An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.
6.1MEDIUM
CVE-2021-41739
all versions
A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events
9.8CRITICAL
CVE-2020-15053
< 4.28.030.418
An issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time request, S
6.1MEDIUM
CVE-2020-15052
< 4.28.030.418
An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alias fields.
7.5HIGH
CVE-2020-15051
< 4.30.000000
An issue was discovered in Artica Proxy before 4.30.000000. Stored XSS exists via the Server Domain Name, Your Email Address, Grou
6.1MEDIUM
CVE-2020-13159
< 4.30.000000
Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_m
9.8CRITICAL
CVE-2020-13158
< 4.30.000000
Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.
7.5HIGH
CVE-2020-10818
all versions
Artica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the hostname"
7.2HIGH
CVE-2019-7300
all versions
Artica Proxy 3.06.200056 allows remote attackers to execute arbitrary commands as root by reading the ressources/settings.inc ldap
7.2HIGH
CVE-2017-17055
< 3.06.112911
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting
9.0CRITICAL
threatengine.sh