Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
工具/GitHubGitHub/emaar1x/cve-2021-41773
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationLabs & Practice
GitHubemaar1x/cve-2021-41773

CVE-2021-41773

Educational Docker lab for Apache HTTP Server 2.4.49 path traversal and RCE (CVE-2021-41773) with CVE research, PoC exploit, testing evidence, and mitigation guidance.

查看仓库
591个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
内容在请求的语言中不可用。显示英文版本。

CVE-2021-41773 — Apache HTTP Server 2.4.49 Path Traversal & RCE

⚠️ For isolated, educational lab use ONLY. This repository builds a deliberately vulnerable Apache server. Never run it on a live, production, or internet-facing host.

Red Team internship project by Team Alpha (ITSOLERA — Offensive Security / Exploit Development for a Known CVE). The work is split across six task folders so each member can contribute via their own pull request.

📄 Final report: 06-final-report/CVE-2021-41773-Final-Report.pdf


The vulnerability in one line

Apache 2.4.49 decodes a %2e-encoded dot after its path-normalisation check, so /files/.%2e/.%2e/.%2e/.%2e/etc/passwd escapes the document root. With mod_cgi enabled, the same trick against /bin/sh gives remote code execution.

  • Affected: Apache HTTP Server 2.4.49 only
  • Incomplete fix: 2.4.50 → CVE-2021-42013 · Fully fixed: 2.4.51
  • CVSS v3.1: 7.5 (file read) / up to 9.8 with CGI enabled (RCE)

Repository structure

FolderOwnerDeliverableStatus
01-cve-research/Fatima Bente MustafaCVE summary, affected versions, root cause, CVSS, references✅ Done
02-lab-setup/Emaar EjazVulnerable Apache 2.4.49 Docker lab + SETUP.md✅ Done
03-vulnerability-analysis/Anum Aamir SajjadANALYSIS.md + evidence-log.txt✅ Done
04-exploit-poc/Noor Saba Basitcve-2021-41773.py + exploit.sh + logic✅ Done
05-testing-evidence/Sana TariqScreenshots, terminal output, server logs✅ Done
06-final-report/Muhammad HammadCompiled final report (PDF) + mitigation✅ Done

Running the lab

The vulnerable target lives in 02-lab-setup/. From inside that folder:

docker build -t cve-2021-41773-lab:2.4.49 .
docker run -d --name apache-2449-vuln -p 127.0.0.1:8080:80 cve-2021-41773-lab:2.4.49

See 02-lab-setup/SETUP.md for the full setup, verification, evidence-collection, and troubleshooting guide.


Mitigation

Upgrade to Apache HTTP Server 2.4.51 or later. As defence in depth, keep <Directory /> at Require all denied by default and only grant access where needed.

下载工具