Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。 Drupal中带有默认或通用模块配置的多个子系统存在安全漏洞。远程攻击者可利用该漏洞执行任意代码。以下版本受到影响:Drupal 7.58之前版本,8.3.9之前的8.x版本,8.4.6之前的8.4.x版本,8.5.1之前的8.5.x版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2018-7600 Drupal RCE | https://github.com/g0rx/CVE-2018-7600-Drupal-RCE | POC Details |
| 2 | 💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002 | https://github.com/a2u/CVE-2018-7600 | POC Details |
| 3 | Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002) | https://github.com/dreadlocked/Drupalgeddon2 | POC Details |
| 4 | CVE-2018-7600 (Drupal) | https://github.com/knqyf263/CVE-2018-7600 | POC Details |
| 5 | Drupal 0day Remote PHP Code Execution (Perl) | https://github.com/dr-iman/CVE-2018-7600-Drupal-0day-RCE | POC Details |
| 6 | MSF exploit module for Drupalgeddon 2 (CVE-2018-7600 / SA-CORE-2018-002) | https://github.com/jirojo2/drupalgeddon2 | POC Details |
| 7 | PoC for CVE-2018-7600 Drupal SA-CORE-2018-002 (Drupalgeddon 2). | https://github.com/dwisiswant0/CVE-2018-7600 | POC Details |
| 8 | Proof-of-Concept for Drupal CVE-2018-7600 / SA-CORE-2018-002 | https://github.com/thehappydinoa/CVE-2018-7600 | POC Details |
| 9 | Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600) | https://github.com/sl4cky/CVE-2018-7600 | POC Details |
| 10 | Tool to check for CVE-2018-7600 vulnerability on several URLS | https://github.com/sl4cky/CVE-2018-7600-Masschecker | POC Details |
| 11 | CVE-2018-7600 - Drupal 7.x RCE | https://github.com/firefart/CVE-2018-7600 | POC Details |
| 12 | Exploit for Drupal 7 <= 7.57 CVE-2018-7600 | https://github.com/pimps/CVE-2018-7600 | POC Details |
| 13 | Exploit for CVE-2018-7600.. called drupalgeddon2, | https://github.com/lorddemon/drupalgeddon2 | POC Details |
| 14 | Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600 | https://github.com/Hestat/drupal-check | POC Details |
| 15 | Vuln checker for Drupal v7.x + v8.x (CVE-2018-7600 / SA-CORE-2018-002) | https://github.com/Damian972/drupalgeddon-2 | POC Details |
| 16 | None | https://github.com/jyo-zi/CVE-2018-7600 | POC Details |
| 17 | None | https://github.com/happynote3966/CVE-2018-7600 | POC Details |
| 18 | MASS Exploiter | https://github.com/shellord/CVE-2018-7600-Drupal-RCE | POC Details |
| 19 | CVE-2018-7600 POC (Drupal RCE) | https://github.com/r3dxpl0it/CVE-2018-7600 | POC Details |
| 20 | cve-2018-7600 | https://github.com/cved-sources/cve-2018-7600 | POC Details |
| 21 | The exploit python script for CVE-2018-7600 | https://github.com/madneal/codeql-scanner | POC Details |
| 22 | CVE-2018-7600 | https://github.com/drugeddon/drupal-exploit | POC Details |
| 23 | CVE-2018-7600 and CVE-2018-7602 Mass Exploiter | https://github.com/shellord/Drupalgeddon-Mass-Exploiter | POC Details |
| 24 | CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本 | https://github.com/zhzyker/CVE-2018-7600-Drupal-POC-EXP | POC Details |
| 25 | CVE-2018-7600【Drupal7】批量扫描工具。 | https://github.com/rabbitmask/CVE-2018-7600-Drupal7 | POC Details |
| 26 | CVE-2018-7600 0-Day Exploit (cyber-warrior.org) | https://github.com/ynsmroztas/drupalhunter | POC Details |
| 27 | CVE-2018-7600 | Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' RCE | https://github.com/ruthvikvegunta/Drupalgeddon2 | POC Details |
| 28 | Drupal 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations. | https://github.com/0xAJ2K/CVE-2018-7600 | POC Details |
| 29 | None | https://github.com/rafaelcaria/drupalgeddon2-CVE-2018-7600 | POC Details |
| 30 | Detect with python and tracking IP | https://github.com/vphnguyen/ANM_CVE-2018-7600 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2015-2002 | ESRI ArcGis Runtime SDK for Android 安全漏洞 | |
| CVE-2017-16873 | Hashicorp vagrant-vmware-fusion 安全漏洞 | |
| CVE-2017-16839 | Hashicorp vagrant-vmware-fusion 安全漏洞 | |
| CVE-2017-16512 | Hashicorp vagrant-vmware-fusion 安全漏洞 | |
| CVE-2016-6658 | Pivotal cf-release 安全漏洞 | |
| CVE-2016-0898 | Pivotal Software MySQL for PCF 信息泄露漏洞 | |
| CVE-2017-5947 | 多款OnePlus One产品OxygenOS 安全漏洞 | |
| CVE-2015-4953 | IBM BigFix Remote Control 加密问题漏洞 | |
| CVE-2015-4952 | IBM Endpoint Manager for Remote Control on-demand插件安全漏洞 | |
| CVE-2015-2020 | MyScript SDK for Android 安全漏洞 | |
| CVE-2015-2009 | IBM QRadar SIEM 跨站请求伪造漏洞 | |
| CVE-2015-2004 | GraceNote GNSDK for Android 安全漏洞 | |
| CVE-2015-2003 | PJSIP PJSUA2 SDK for Android 安全漏洞 | |
| CVE-2018-9120 | Crea8social 跨站脚本漏洞 | |
| CVE-2015-2001 | MetaIO SDK for Android 安全漏洞 | |
| CVE-2015-2000 | Jumio SDK for Android 安全漏洞 | |
| CVE-2014-6604 | WordPress Subscribe2插件跨站脚本漏洞 | |
| CVE-2014-5170 | Drupal Storage API模块安全漏洞 | |
| CVE-2014-5028 | Beanbag Review Board 安全漏洞 | |
| CVE-2018-9031 | TNLSoftSolutions Sentry 安全漏洞 |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet