mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-19 17:30:12 +00:00
992 B
992 B
CVE-2024-2054
Description
The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.
POC
Reference
- http://seclists.org/fulldisclosure/2024/Mar/12
- http://seclists.org/fulldisclosure/2024/Mar/12
- https://korelogic.com/Resources/Advisories/KL-001-2024-002.txt
- https://korelogic.com/Resources/Advisories/KL-001-2024-002.txt