Cybersecurity lab demonstrating Apache CVE-2021-41773 path traversal vulnerability with vulnerable server simulation, scanner, and security reporting.
This project is a cybersecurity research laboratory designed to demonstrate the real-world impact of software vulnerabilities through controlled exploitation and defensive patch simulation.
The lab focuses on CVE-2021-41773, a critical path traversal vulnerability in Apache HTTP Server that allows attackers to access sensitive files outside the web root. The environment includes both a vulnerable server simulation and a patched secure implementation to highlight the importance of proper input normalization and secure configuration practices.
The project is intended for educational, ethical hacking, and cybersecurity research purposes only.
CVE_LAB/
│
├── exploit_CVE_2021_41773.py → Automated vulnerability scanner & report generator
├── vulnerable_server.py → Simulated Apache server with path traversal flaw
├── patched_server.py → Secure server implementation blocking traversal
├── requirements.txt → Python dependencies
└── reports/ → Generated vulnerability reports
Install dependencies:
pip install -r requirements.txt
python vulnerable_server.py
Server runs locally on:
http://localhost:8000
python exploit_CVE_2021_41773.py --target http://localhost:8000
The scanner will:
python patched_server.py
The exploit should now fail, demonstrating effective mitigation.
Through this lab, learners gain hands-on experience with:
This project is strictly intended for:
Do not use this tool against systems without explicit authorization.
Developed as part of hands-on cybersecurity research focusing on reconnaissance automation and offensive security tooling.
This project is released for educational use and research purposes.