Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-37153 PoC — Artica Proxy 跨站脚本漏洞

Source
Associated Vulnerability
Title:Artica Proxy 跨站脚本漏洞 (CVE-2022-37153)
Description:Artica Proxy是法国Artica公司的一款开源的Artica代理解决方案。 Artica Proxy 4.30.0000版本存在跨站脚本漏洞,该漏洞源于/fw.login.php中的密码参数存在一个XSS漏洞。
Description
There is a XSS  vulnerability  in Artica Proxy 4.30.000000
Readme
# CVE-2022-37153
There is a XSS  vulnerability  in Artica Proxy 4.30.000000

vulname:              Artica Proxy reflected XSS

vulnerable page:      /fw.login.php

vulnerable param:     password

payload:              "><script>alert(1)</script>

FOFA:                 icon_hash="-27821316"
File Snapshot

[4.0K] /data/pocs/bf61d767ee4a4ca7fc77f8c8d6ffde6729cdc2bf ├── [753K] Artica Proxy Reflected XSS.docx ├── [3.2M] Artica Proxy Reflected XSS.mp4 └── [ 291] README.md 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.