CVE-2020-13158
articatech artica_proxy Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2020-13158 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
artica_proxyBrowse articatech / artica_proxy | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubInfoSec4Fun/CVE-2020-13158Repository PoCby InfoSec4FunStars: 1Not analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHArtica Proxy Community Edition <4.30.000000 - Local File InclusionCVSS 7.5
Artica Proxy Community Edition before 4.30.000000 is vulnerable to local file inclusion via the fw.progrss.details.php popup parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to read arbitrary files on the server, potentially leading to further compromise of the system.
Remediation
Upgrade to Artica Proxy Community Edition version 4.30.000000 or later to fix the Local File Inclusion vulnerability.
Source: ProjectDiscovery