Reads /etc/passwd through URL-encoded path traversal sequences in Apache's CGI handler, proving arbitrary file read on the server.
Is your app exploitable through CVE-2021-41773?