Apache HTTP Server 2.4.50 with mod_cgi enabled and `Require all granted` on the root directory, vulnerable to CVE-2021-42013: the fix for CVE-2021-41773 misses double URL encoding (%%32%65), so a request walks out of the document root to read files or reach /bin/sh as a CGI script.
Not startedDockercommit 0c828ecx86_64 · aarch64Secret
Exploit CVE-2021-42013 to run commands on the Apache server and get a shell.
The brief for this lab lives in its repository.