Apache HTTP Server 2.4.38
Built from source with mod_auth_digest and mod_cgi enabled. Configured to protect /scripts/userprofile.cgi with Digest authentication using a password file containing two users: victim and attacker.
sample_vulnerable_server/Dockerfile:7-12sample_vulnerable_server/Dockerfile:18-35