Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17505
Reference (s):
- http://packetstormsecurity.com/files/159267/Artica-Proxy-4.30.000000-Authentication-Bypass-Command-Injection.html
- https://blog.max0x4141.com/post/artica_proxy/

