
cve-2021-41773 即 cve-2021-42013 批量检测脚本
cve-2021-41773 and cve-2021-42013 batch verification Python script
Runtime environment: python3
Usage: python3 poc.py url.txt
url.txt contains the URLs to be tested, and URLs with vulnerabilities will be written to success.txt
The verification content is very simple: send a GET request to cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/etc/passwd. However, I found that using requests to send the packet didn't work. Upon packet capture, I discovered that %2e was automatically decoded to .. So I switched to using urllib to send the packet, which worked fine and passed local testing.