
Exploit CVE-2021-41773 and CVE-2021-42013
This repository focuses on exploiting two vulnerabilities in Apache HTTPD: CVE-2021-41773 and CVE-2021-42013. These CVEs represent path traversal vulnerabilities that can potentially lead to file mapping and remote code execution on Apache HTTPD servers. For in-depth information about these CVEs, including the underlying flaws, vulnerable configurations, exploits, and more, refer to this comprehensive blog post: Dissecting and Exploiting CVE-2021-41773 and CVE-2021-42013.
To successfully exploit these vulnerabilities, you'll need:
To get started:
git clone https://github.com/OfriOuzan/CVE-2021-41773_CVE-2021-42013_Exploits
cd CVE-2021-41773_CVE-2021-42013_Exploits
python3 exploit.p
This repository comprises four distinct directories, each responsible for constructing a different container for exploitation purposes:
Within each directory, you'll find a Dockerfile to facilitate container creation and a httpd.conf contains the specific vulnerable configurations. This repository aims to provide a practical environment for understanding and studying these vulnerabilities.
The exploit.py file performs the exploitation in two stages: