CVE-2021-41739: Command Injection
A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41739?
CVE-2021-41739 has a high severity due to its OS Command Injection vulnerability that can be exploited by attackers.
How do I fix CVE-2021-41739?
To fix CVE-2021-41739, upgrade Artica Proxy to a version that addresses this vulnerability, ensuring input validation for parameters.
What is affected by CVE-2021-41739?
CVE-2021-41739 affects Artica Proxy version 4.30.000000, allowing the execution of OS commands through specific parameters.
Can CVE-2021-41739 be exploited remotely?
Yes, CVE-2021-41739 can be exploited remotely, enabling attackers to execute commands on the server.
Is there a workaround for CVE-2021-41739?
A temporary workaround for CVE-2021-41739 may include disabling the affected functionality until a software patch can be applied.