VYPR

Proxy CE

by Artica

CVEs (6)

  • CVE-2021-40680HigApr 25, 2022
    risk 0.53cvss 8.1epss 0.01

    There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30.000000 through SP273) via the filename parameter to /cgi-bin/main.cgi.

  • CVE-2020-15052HigJul 20, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alias fields.

  • CVE-2020-10818HigMar 22, 2020
    risk 0.47cvss 7.2epss 0.03

    Artica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the hostname" field.

  • CVE-2019-7300HigFeb 1, 2019
    risk 0.47cvss 7.2epss 0.03

    Artica Proxy 3.06.200056 allows remote attackers to execute arbitrary commands as root by reading the ressources/settings.inc ldap_admin and ldap_password fields, using these credentials at logon.php, and then entering the commands in the admin.index.php command-line field.

  • CVE-2022-37153MedAug 24, 2022
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.

  • CVE-2026-66745HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior to authentication. Attackers…