Description
A Command Injection vulnerability in Artica Proxy appliance version 4.50 and 4.40 allows remote attackers to run arbitrary commands via unauthenticated HTTP request. The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/artica/proxy_unauth_rce_cve_2024_2054msf undefined(proxy_unauth_rce_cve_2024_2054) > show actions ...actions...msf undefined(proxy_unauth_rce_cve_2024_2054) > set ACTION < action-name >msf undefined(proxy_unauth_rce_cve_2024_2054) > show options ...show and set options...msf undefined(proxy_unauth_rce_cve_2024_2054) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub