Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-41773 — Detailed writeup of CVE-2021-41773 Apache path traversal and RCE exploitation, with step-by-step commands and root cause analysis from a TryHackMe lab environment. | Kitploit
Tools/GitHubGitHub/johnwickakash12/cve-2021-41773
Vulnerability AnalysisExploitationWeb Application ExploitationCTFLearning & EducationLabs & Practice
GitHubjohnwickakash12/cve-2021-41773

CVE-2021-41773

Detailed writeup of CVE-2021-41773 Apache path traversal and RCE exploitation, with step-by-step commands and root cause analysis from a TryHackMe lab environment.

View Repository
82 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-41773 — Apache Path Traversal & RCE Exploitation

Writeup of the TryHackMe "Modern Web Stacks" room, focused on exploiting CVE-2021-41773, a path traversal vulnerability in Apache HTTP Server 2.4.49 that leads to remote code execution when mod_cgi is enabled.

Summary

ItemDetail
VulnerabilityCVE-2021-41773 — Apache 2.4.49 Path Traversal / RCE
Target serviceApache HTTP Server on port 8080
Vulnerable versionApache/2.4.49 (Unix)
Root causeBroken normalization order in ap_normalize_path()
ImpactArbitrary file read → Remote Code Execution via mod_cgi
Tools usedcurl

Vulnerability Overview

Apache 2.4.49 changed how ap_normalize_path() processes URLs. Apache is supposed to block any request path containing ../ before it reaches the filesystem — but the traversal filter runs before full URL decoding takes place.

This means a request using the double-encoded sequence .%2e/ is not recognized as ../ by the filter. However, once Apache hands the path to the OS, .%2e/ is resolved to ../, and the traversal filter has already been bypassed.

On its own this allows arbitrary file reads outside the web root. The impact becomes critical when combined with mod_cgi: if the traversal path resolves to an executable like /bin/sh inside a CGI-enabled directory (e.g. /cgi-bin/), Apache executes it as a CGI script and passes the HTTP POST body to its stdin — giving remote command execution.

Steps

1. Confirm the vulnerable Server header

Identified the target's Server response header as:

Apache/2.4.49 (Unix)

This version is directly affected by CVE-2021-41773.

2. Check /cgi-bin/ availability

Requested /cgi-bin/ and received a 403 Forbidden response (not a 404), indicating the directory exists and mod_cgi is likely enabled — a precondition for RCE via this CVE.

3. Exploit the path traversal for RCE

Used curl with the --path-as-is flag to send the encoded traversal sequence exactly as typed, without curl normalizing it client-side first:

curl -s --path-as-is "http://<TARGET_IP>:8080/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh" \
  --data 'echo Content-Type: text/plain; echo; cat /flag.txt'

Why --path-as-is is required: by default, curl normalizes URLs and strips .%2e/ sequences before the request is even sent. --path-as-is tells curl to send the URL exactly as written, preserving the encoded traversal so it reaches the server intact.

4. Read the flag

The payload traversed out of /cgi-bin/ to the root filesystem, executed /bin/sh as a CGI script via the injected POST body, and returned the contents of /flag.txt.

Flag format confirmed: THM{...}

(Flag redacted per TryHackMe's guidelines on public writeups.)

Key Takeaways

  • Patch order matters. A security filter that runs before decoding is complete can be trivially bypassed with encoding tricks — this exact pattern (filter-then-decode vs decode-then-filter) shows up across many traversal CVEs, not just this one.
  • mod_cgi + path traversal = RCE. File read alone is bad; combined with a CGI-executable directory, it becomes command execution.
  • Tooling behavior matters during testing. curl's default URL normalization can silently "fix" the exact payload you're trying to send — --path-as-is (or an equivalent raw-request tool) is essential when testing encoding-based bypasses.

Remediation

  • Upgrade Apache to 2.4.51 or later (fixes both CVE-2021-41773 and the related CVE-2021-42013).
  • Disable mod_cgi unless explicitly required.
  • Apply the principle of least privilege to the web server process to limit blast radius of any file-read primitive.

References

  • CVE-2021-41773 — NVD
  • TryHackMe — Modern Web Stacks room

This writeup documents a lab environment (TryHackMe). No unauthorized systems were accessed.

Download Tool