vendor:
Drupal
by:
Vitalii Rudnykh
9.8
CVSS
CRITICAL
Remote Code Execution
94
CWE
Product Name: Drupal
Affected Version From: Drupal 7.x and 8.x
Affected Version To: Drupal 8.5.1 and 7.58
Patch Exists: YES
Related CWE: CVE-2018-7600
CPE: a:drupal:drupal
Other Scripts:
N/A
Platforms Tested: None
2018
Proof-Of-Concept for CVE-2018-7600
This exploit is a proof-of-concept for CVE-2018-7600, a vulnerability in Drupal 7.x and 8.x. It allows an attacker to execute arbitrary code on the target system by sending a specially crafted request to the target server. The exploit works by sending a POST request to the target server with a specially crafted payload. The payload contains a command to execute arbitrary code, which is then executed on the target system.
Mitigation:
Upgrade to Drupal 8.5.1 or later, or Drupal 7.58 or later.