openkylin-exploit-db/cve/apache/2021/CVE-2021-42013
yangjipeng 66924aad54 ADD CVE-2021-42013 2022-10-24 11:04:29 +08:00
..
PoC.sh ADD CVE-2021-42013 2022-10-24 11:04:29 +08:00
README.md ADD CVE-2021-42013 2022-10-24 11:04:29 +08:00
apache.png ADD CVE-2021-42013 2022-10-24 11:04:29 +08:00

README.md

Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE

Exploit Author: Lucas Souza https://lsass.io
Vendor Homepage: https://apache.org/
Version: 2.4.49, 2.4.50
Tested on: 2.4.49, 2.4.50
CVE : CVE-2021-41773, CVE-2021-42013
Credits: Ash Daulton and the cPanel Security Team

Usage

 ./PoC.sh targets.txt /etc/passwd

 ./PoC.sh targets.txt /bin/sh "id"