HTTP: Artica Proxy images.listener.php Arbitrary File Read

This signature detects attempts to exploit a known vulnerability against Artica. A successful attack can lead to sensitive information disclosure.

Extended Description

The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user. This issue was demonstrated on version 4.50 of theThe Artica-Proxy administrative web application attempts to prevent local file inclusion. These protections can be bypassed and arbitrary file requests supplied by unauthenticated users will be returned according to the privileges of the "www-data" user.

Short Name
HTTP:CTS:ARTICA-PROXY-FL-UPLOAD
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Arbitrary Artica CVE-2024-2053 File Proxy Read images.listener.php
Release Date
05/16/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3783
False Positive
Unknown

Found a potential security threat?