S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-13158 Scanner

Exploits the fw.progrss.details.php popup parameter to read arbitrary files on the server, bypassing access controls.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-13158
7.5
CVSS

Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Artica Proxy is a comprehensive proxy server solution used by organizations to filter, cache, and control internet traffic. It provides network administrators with tools to enforce security policies, monitor usage, and optimize bandwidth. The Community Edition is a free, open-source version widely deployed in small to medium businesses for its robust features without licensing costs.

CVE-2020-13158 is a directory traversal vulnerability that arises from insufficient input validation in the fw.progrss.details.php script. The popup parameter fails to sanitize user-supplied paths, allowing an attacker to traverse directories using sequences like ../. This flaw enables unauthorized access to files outside the intended web root.

Specifically, the vulnerable endpoint is /fw.progrss.details.php, where the popup parameter accepts a file path without proper filtering. An attacker can craft a request such as /fw.progrss.details.php?popup=../../etc/passwd to retrieve sensitive system files. The vulnerability exists in Artica Proxy Community Edition versions before 4.30.0.

If exploited, an attacker can read arbitrary files on the server, including configuration files, credentials, and sensitive data. This could lead to privilege escalation, data breaches, or further compromise of the network. The CVSS score of 7.5 reflects the high impact and ease of exploitation, making it critical to address promptly.

Solution Advice
  • Upgrade Artica Proxy Community Edition to version 4.30.0 or later, which includes a fix for this vulnerability.
  • Implement input validation on the popup parameter to reject directory traversal sequences like ../.
  • Apply web application firewall (WAF) rules to block malicious requests targeting fw.progrss.details.php.
  • Restrict file system permissions to limit the impact of directory traversal attacks.
  • Monitor logs for unusual access patterns to fw.progrss.details.php with path traversal attempts.
  • Conduct regular vulnerability scans using tools like S4E to detect and remediate similar issues.
  • Disable or remove unnecessary scripts like fw.progrss.details.php if not required for operations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.