漏洞描述 10月4日,Apache 发布了 Apache HTTP Server 2.4.50 版本,旨在解决Apache HTTP Server 2.4.49版本的CVE-2021-41773(Apache HTTP Server路径遍历漏洞),同时,该漏洞利用细节被公开,攻击者可以使用路径遍历攻击读取根目录之外的文件。研究人员发现之前的安全更新没有正确修复该漏洞,并在2.4.49和2.4.50版本中均存在漏洞。
相关漏洞推荐 POC cl-te-http-smuggling: Basic CL.TE - HTTP request smuggling POC te-cl-http-smuggling: Basic TE.CL - HTTP Request Smuggling POC CVE-2001-0537: Cisco IOS HTTP Configuration - Authentication Bypass POC CVE-2006-1681: Cherokee HTTPD <=0.5 - Cross-Site Scripting POC CVE-2014-2323: Lighttpd 1.4.34 SQL Injection and Path Traversal POC CVE-2017-15715: Apache httpd <=2.4.29 - Arbitrary File Upload POC CVE-2018-16133: Cybrotech CyBroHttpServer 1.0.3 - Local File Inclusion POC CVE-2018-18778: ACME mini_httpd <1.30 - Local File Inclusion POC CVE-2019-10092: Apache HTTP Server <=2.4.39 - HTML Injection/Partial Cross-Site Scripting POC CVE-2019-10098: Apache HTTP server v2.4.0 to v2.4.39 - Open Redirect POC CVE-2020-11984: Apache HTTP Server - Remote Code Execution POC CVE-2024-23334: aiohttp - Directory Traversal POC CVE-2024-23692: Rejetto HTTP File Server - Template injection