# N/A
## 漏洞概述
Drupal多个版本中存在代码执行漏洞,该漏洞影响了多个子系统,且默认或常见的模块配置均受影响,允许远程攻击者执行任意代码。
## 影响版本
- Drupal 7.x 版本:<7.58
- Drupal 8.x 版本:<8.3.9
- Drupal 8.4.x 版本:<8.4.6
- Drupal 8.5.x 版本:<8.5.1
## 细节
该漏洞存在于多个子系统中,由于默认或常见的模块配置情况下,远程攻击者能够利用漏洞执行任意代码。
## 影响
攻击者可以利用此漏洞在受影响的Drupal站点上执行任意代码,可能导致完全控制网站服务器和其他严重后果,例如植入后门、资料泄露或网站被篡改等。
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | CVE-2018-7600 Drupal RCE | https://github.com/g0rx/CVE-2018-7600-Drupal-RCE | POC详情 |
2 | 💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002 | https://github.com/a2u/CVE-2018-7600 | POC详情 |
3 | Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002) | https://github.com/dreadlocked/Drupalgeddon2 | POC详情 |
4 | CVE-2018-7600 (Drupal) | https://github.com/knqyf263/CVE-2018-7600 | POC详情 |
5 | Drupal 0day Remote PHP Code Execution (Perl) | https://github.com/dr-iman/CVE-2018-7600-Drupal-0day-RCE | POC详情 |
6 | MSF exploit module for Drupalgeddon 2 (CVE-2018-7600 / SA-CORE-2018-002) | https://github.com/jirojo2/drupalgeddon2 | POC详情 |
7 | PoC for CVE-2018-7600 Drupal SA-CORE-2018-002 (Drupalgeddon 2). | https://github.com/dwisiswant0/CVE-2018-7600 | POC详情 |
8 | Proof-of-Concept for Drupal CVE-2018-7600 / SA-CORE-2018-002 | https://github.com/thehappydinoa/CVE-2018-7600 | POC详情 |
9 | Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600) | https://github.com/sl4cky/CVE-2018-7600 | POC详情 |
10 | Tool to check for CVE-2018-7600 vulnerability on several URLS | https://github.com/sl4cky/CVE-2018-7600-Masschecker | POC详情 |
11 | CVE-2018-7600 - Drupal 7.x RCE | https://github.com/firefart/CVE-2018-7600 | POC详情 |
12 | Exploit for Drupal 7 <= 7.57 CVE-2018-7600 | https://github.com/pimps/CVE-2018-7600 | POC详情 |
13 | Exploit for CVE-2018-7600.. called drupalgeddon2, | https://github.com/lorddemon/drupalgeddon2 | POC详情 |
14 | Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600 | https://github.com/Hestat/drupal-check | POC详情 |
15 | Vuln checker for Drupal v7.x + v8.x (CVE-2018-7600 / SA-CORE-2018-002) | https://github.com/Damian972/drupalgeddon-2 | POC详情 |
16 | None | https://github.com/jyo-zi/CVE-2018-7600 | POC详情 |
17 | None | https://github.com/happynote3966/CVE-2018-7600 | POC详情 |
18 | MASS Exploiter | https://github.com/shellord/CVE-2018-7600-Drupal-RCE | POC详情 |
19 | CVE-2018-7600 POC (Drupal RCE) | https://github.com/r3dxpl0it/CVE-2018-7600 | POC详情 |
20 | cve-2018-7600 | https://github.com/cved-sources/cve-2018-7600 | POC详情 |
21 | The exploit python script for CVE-2018-7600 | https://github.com/madneal/codeql-scanner | POC详情 |
22 | CVE-2018-7600 | https://github.com/drugeddon/drupal-exploit | POC详情 |
23 | CVE-2018-7600 and CVE-2018-7602 Mass Exploiter | https://github.com/shellord/Drupalgeddon-Mass-Exploiter | POC详情 |
24 | CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本 | https://github.com/zhzyker/CVE-2018-7600-Drupal-POC-EXP | POC详情 |
25 | CVE-2018-7600【Drupal7】批量扫描工具。 | https://github.com/rabbitmask/CVE-2018-7600-Drupal7 | POC详情 |
26 | CVE-2018-7600 0-Day Exploit (cyber-warrior.org) | https://github.com/ynsmroztas/drupalhunter | POC详情 |
27 | CVE-2018-7600 | Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' RCE | https://github.com/ruthvikvegunta/Drupalgeddon2 | POC详情 |
28 | Drupal 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations. | https://github.com/0xAJ2K/CVE-2018-7600 | POC详情 |
29 | None | https://github.com/rafaelcaria/drupalgeddon2-CVE-2018-7600 | POC详情 |
30 | Detect with python and tracking IP | https://github.com/vphnguyen/ANM_CVE-2018-7600 | POC详情 |
31 | None | https://github.com/0xConstant/CVE-2018-7600 | POC详情 |
32 | None | https://github.com/anldori/CVE-2018-7600 | POC详情 |
33 | Drupal CVE-2018-7600 RCE Pseudo-Shell PoC | https://github.com/r0lh/CVE-2018-7600 | POC详情 |
34 | CVE-2018-7600 漏洞验证和利用 | https://github.com/killeveee/CVE-2018-7600 | POC详情 |
35 | None | https://github.com/soch4n/CVE-2018-7600 | POC详情 |
36 | None | https://github.com/raytran54/CVE-2018-7600 | POC详情 |
37 | None | https://github.com/banomaly/CVE-2018-7600 | POC详情 |
38 | CVE-2018-7600. | https://github.com/mr-won/CVE-2018-7600. | POC详情 |
39 | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-7600.yaml | POC详情 |
40 | None | https://github.com/Threekiii/Awesome-POC/blob/master/CMS%E6%BC%8F%E6%B4%9E/Drupal%20Drupalgeddon%202%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2018-7600.md | POC详情 |
41 | https://github.com/vulhub/vulhub/blob/master/drupal/CVE-2018-7600/README.md | POC详情 | |
42 | CVE-2018-7600. | https://github.com/user20252228/CVE-2018-7600. | POC详情 |
43 | CVE-2018-7600. | https://github.com/tpdlshdmlrkfmcla/CVE-2018-7600. | POC详情 |
44 | None | https://github.com/Dowonkwon/drupal-cve-2018-7600-poc | POC详情 |
45 | For Home Lab and Educational Purpose only not intended for any Harmful intenstions purely for educational purpose | https://github.com/M-Abid34/CVE-2018-7600 | POC详情 |
46 | This repository contains a completely original and self-developed Proof-of-Concept (PoC) for CVE-2018-7600, also known as Drupalgeddon 2 — a critical remote code execution vulnerability affecting Drupal 7 and 8 core versions. | https://github.com/rajaabdullahnasir/CVE-2018-7600-Remote-Code-Execution | POC详情 |
暂无评论