Apache HTTP Server 2.4.49 with CGI enabled, vulnerable to CVE-2021-41773: a path normalization bug lets encoded dot segments escape the document root, to read files and, through mod_cgi, run commands.
Not startedDockercommit 04bc2f4x86_64 · aarch64Secret
Exploit CVE-2021-41773 to read files outside the web root, then run a command on the server.
The brief for this lab lives in its repository.