Now, just to repeat the scan with: Referer: () { :; }; sudo apt-get update && sudo apt-get install --only-upgrade bash "Why, who was that masked sysadmin? We didn't even get the chance to thank him."
Who would grant `sudo` privileges to `www-data` without asking for a password? That's just asking for a bad time.
if their httpd.conf has incorrect privs set, you could run a script that changes the "user to run as" to root, then set up a script that would run on next reboot to apt-get upgrade and remove the root privs config line. you'd have to wait for the server to go down or reboot however long in the future, but hey it would work.