
إثبات مفهوم الاستغلال لـ CVE-2021-41773، وهو ثغرة اجتياز المسار في خادم Apache HTTP Server 2.4.49 تتيح كشف الملفات عن بُعد وتنفيذ CGI.
ثغرة أمنية في خادم Apache HTTP (تعمل فقط على الإصدار 2.4.49)
httpd.conf
...
<IfModule mpm_prefork_module>
LoadModule cgi_module modules/mod_cgi.so # uncomment this line
</IfModule>
...
<Directory />
AllowOverride none
# Require all denied # comment out this line or set `Require all granted`
</Directory>
...