mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-31 10:40:54 +00:00
876 B
876 B
CVE-2024-2054
Description
The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.
POC
Reference
- http://seclists.org/fulldisclosure/2024/Mar/12
- https://korelogic.com/Resources/Advisories/KL-001-2024-002.txt