CVE-2024-2053

HIGH EXPLOITED NUCLEI

Artica Proxy - Unauthenticated Arbitrary File Read via Local File Inclusion Bypass

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-2053 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including b-L-x. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2024-2053, targeting Artica Proxy's LFI vulnerability to achieve RCE via log poisoning. The exploit includes methods for testing LFI, injecting PHP payloads into logs, and writing a webshell.

Description

The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user. This issue was demonstrated on version 4.50 of the The Artica-Proxy administrative web application attempts to prevent local file inclusion. These protections can be bypassed and arbitrary file requests supplied by unauthenticated users will be returned according to the privileges of the "www-data" user.

Exploits (1)

nomisec WORKING POC
by b-L-x · remote
https://github.com/b-L-x/CVE-2024-2053

This repository contains a functional Python exploit for CVE-2024-2053, targeting Artica Proxy's LFI vulnerability to achieve RCE via log poisoning. The exploit includes methods for testing LFI, injecting PHP payloads into logs, and writing a webshell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Artica Proxy 4.50
No auth needed
Prerequisites: Access to the vulnerable endpoint · Ability to write to server logs
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Nuclei Templates (1)

Artica Proxy - Unauthenticated LFI
HIGHVERIFIEDby pussycat0x
Shodan: http.html:"artica"
FOFA: body="artica"

References (2)

Core 2
Core References
Exploit, Third Party Advisory third-party-advisory
https://korelogic.com/Resources/Advisories/KL-001-2024-001.txt

Scores

CVSS v3 7.5
EPSS 0.3654
EPSS Percentile 97.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2026-02-02
CWE
CWE-23
Status published
Products (2)
articatech/artica_proxy 4.40.000000
articatech/artica_proxy 4.50.000000
Published Mar 21, 2024
Tracked Since Feb 18, 2026