目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2018-7600— Drupal 安全漏洞

一分钟漏洞结论

影响对象
n/a Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1
利用判断
已确认在野利用,应立即处置
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。 Drupal中带有默认或通用模块配置的多个子系统存在安全漏洞。远程攻击者可利用该漏洞执行任意代码。以下版本受到影响:Drupal 7.58之前版本,8.3.9之前的8.x版本,8.4.6之前的8.4.x版本,8.5.1之前的8.5.x版本。

AI 预测 9.8 利用难度: 较易 KEV · 勒索软件 EPSS 99.99% · P100
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2018-7600 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Drupal 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。 Drupal中带有默认或通用模块配置的多个子系统存在安全漏洞。远程攻击者可利用该漏洞执行任意代码。以下版本受到影响:Drupal 7.58之前版本,8.3.9之前的8.x版本,8.4.6之前的8.4.x版本,8.5.1之前的8.5.x版本。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
- Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 -

二、漏洞 CVE-2018-7600 的公开POC

# POC 描述 源链接 神龙链接
1 CVE-2018-7600 Drupal RCE https://github.com/g0rx/CVE-2018-7600-Drupal-RCE POC详情
2 💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002 https://github.com/a2u/CVE-2018-7600 POC详情
3 Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002) https://github.com/dreadlocked/Drupalgeddon2 POC详情
4 CVE-2018-7600 (Drupal) https://github.com/knqyf263/CVE-2018-7600 POC详情
5 Drupal 0day Remote PHP Code Execution (Perl) https://github.com/dr-iman/CVE-2018-7600-Drupal-0day-RCE POC详情
6 MSF exploit module for Drupalgeddon 2 (CVE-2018-7600 / SA-CORE-2018-002) https://github.com/jirojo2/drupalgeddon2 POC详情
7 PoC for CVE-2018-7600 Drupal SA-CORE-2018-002 (Drupalgeddon 2). https://github.com/dwisiswant0/CVE-2018-7600 POC详情
8 Proof-of-Concept for Drupal CVE-2018-7600 / SA-CORE-2018-002 https://github.com/thehappydinoa/CVE-2018-7600 POC详情
9 Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600) https://github.com/sl4cky/CVE-2018-7600 POC详情
10 Tool to check for CVE-2018-7600 vulnerability on several URLS https://github.com/sl4cky/CVE-2018-7600-Masschecker POC详情
11 CVE-2018-7600 - Drupal 7.x RCE https://github.com/firefart/CVE-2018-7600 POC详情
12 Exploit for Drupal 7 <= 7.57 CVE-2018-7600 https://github.com/pimps/CVE-2018-7600 POC详情
13 Exploit for CVE-2018-7600.. called drupalgeddon2, https://github.com/lorddemon/drupalgeddon2 POC详情
14 Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600 https://github.com/Hestat/drupal-check POC详情
15 Vuln checker for Drupal v7.x + v8.x (CVE-2018-7600 / SA-CORE-2018-002) https://github.com/Damian972/drupalgeddon-2 POC详情
16 None https://github.com/jyo-zi/CVE-2018-7600 POC详情
17 None https://github.com/happynote3966/CVE-2018-7600 POC详情
18 MASS Exploiter https://github.com/shellord/CVE-2018-7600-Drupal-RCE POC详情
19 CVE-2018-7600 POC (Drupal RCE) https://github.com/r3dxpl0it/CVE-2018-7600 POC详情
20 cve-2018-7600 https://github.com/cved-sources/cve-2018-7600 POC详情
21 The exploit python script for CVE-2018-7600 https://github.com/madneal/codeql-scanner POC详情
22 CVE-2018-7600 https://github.com/drugeddon/drupal-exploit POC详情
23 CVE-2018-7600 and CVE-2018-7602 Mass Exploiter https://github.com/shellord/Drupalgeddon-Mass-Exploiter POC详情
24 CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本 https://github.com/zhzyker/CVE-2018-7600-Drupal-POC-EXP POC详情
25 CVE-2018-7600【Drupal7】批量扫描工具。 https://github.com/rabbitmask/CVE-2018-7600-Drupal7 POC详情
26 CVE-2018-7600 0-Day Exploit (cyber-warrior.org) https://github.com/ynsmroztas/drupalhunter POC详情
27 CVE-2018-7600 | Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' RCE https://github.com/ruthvikvegunta/Drupalgeddon2 POC详情
28 Drupal 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations. https://github.com/0xAJ2K/CVE-2018-7600 POC详情
29 None https://github.com/rafaelcaria/drupalgeddon2-CVE-2018-7600 POC详情
30 Detect with python and tracking IP https://github.com/vphnguyen/ANM_CVE-2018-7600 POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2018-7600 的情报信息

登录查看更多情报信息。

CVE-2018-7600 厂商安全公告 (3)

CVE-2018-7600 公开利用代码 (3)

CVE-2018-7600 邮件列表归档 (1)

CVE-2018-7600 安全博客文章 (2)

CVE-2018-7600 其他参考 (11)

同批安全公告 · n/a · 2018-03-29 · 共 26 条

CVE-2015-2002 ESRI ArcGis Runtime SDK for Android 安全漏洞
CVE-2017-16873 Hashicorp vagrant-vmware-fusion 安全漏洞
CVE-2017-16839 Hashicorp vagrant-vmware-fusion 安全漏洞
CVE-2017-16512 Hashicorp vagrant-vmware-fusion 安全漏洞
CVE-2016-6658 Pivotal cf-release 安全漏洞
CVE-2016-0898 Pivotal Software MySQL for PCF 信息泄露漏洞
CVE-2017-5947 多款OnePlus One产品OxygenOS 安全漏洞
CVE-2015-4953 IBM BigFix Remote Control 加密问题漏洞
CVE-2015-4952 IBM Endpoint Manager for Remote Control on-demand插件安全漏洞
CVE-2015-2020 MyScript SDK for Android 安全漏洞
CVE-2015-2009 IBM QRadar SIEM 跨站请求伪造漏洞
CVE-2015-2004 GraceNote GNSDK for Android 安全漏洞
CVE-2015-2003 PJSIP PJSUA2 SDK for Android 安全漏洞
CVE-2018-9120 Crea8social 跨站脚本漏洞
CVE-2015-2001 MetaIO SDK for Android 安全漏洞
CVE-2015-2000 Jumio SDK for Android 安全漏洞
CVE-2014-6604 WordPress Subscribe2插件跨站脚本漏洞
CVE-2014-5170 Drupal Storage API模块安全漏洞
CVE-2014-5028 Beanbag Review Board 安全漏洞
CVE-2018-9031 TNLSoftSolutions Sentry 安全漏洞

显示前 20 条,共 26 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2018-7600

暂无评论


发表评论