QID 150373
Date Published: 2021-10-19
QID 150373: Apache HTTP Server Remote Code Execution (CVE-2021-41773)
The Apache HTTP Server, colloquially called Apache, is a free and open-source cross-platform web server software.
The affected version of the Apache server allows remote attackers to read files via a Path Traversal vulnerability. This vulnerability only impacts Apache HTTP Server version 2.4.49 with the Require all denied access control configuration disabled. When mod_cgi module is enabled for these aliased paths, it leads to Remote Code Execution on the target server.
QID Detection Logic (Unauthenticated) :
This QID sends a crafted HTTP POST request to /bin/sh with payload to check if the target is exploitable.
Successful exploitation of the vulnerability will allow remote attacker to execute arbitrary code on the target system.
- Apache HTTP Server -
httpd.apache.org/security/vulnerabilities_24.html
CVEs related to QID 150373
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache HTTP Server |
|