CVE-2020-17506 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 94% (pctl 100)
Patch early
A public exploit exists.
Description
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 93.97% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-08-12 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| articatech | web proxy |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Artica Proxy 4.3.0 - Authentication Bypass | 2020-08-13 |
References
- http://packetstormsecurity.com/files/158868/Artica-Proxy-4.3.0-Authentication-Bypass.html
- http://packetstormsecurity.com/files/159267/Artica-Proxy-4.30.000000-Authentication-Bypass-Command-Injection.html
- https://blog.max0x4141.com/post/artica_proxy/
- http://packetstormsecurity.com/files/158868/Artica-Proxy-4.3.0-Authentication-Bypass.html
- http://packetstormsecurity.com/files/159267/Artica-Proxy-4.30.000000-Authentication-Bypass-Command-Injection.html
- https://blog.max0x4141.com/post/artica_proxy/
→ the Explorer · watch your stack · NVD