All verified exploits

CVE-2021-42013 Path Traversal and File Disclosure

Deterministic critical Apache CISA KEV Added cve-verified-cve-2021-42013

Reads /etc/passwd through a double-encoded dot sequence. Apache 2.4.50 stopped the single-encoded form and still accepted this one.

Is your app exploitable through CVE-2021-42013?

Scan your domain free