Drupal core是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。 Drupal core 7.62之前的7.x版本、8.6.6之前的8.6.x版本和8.5.9之前的8.5.x版本中的内置phar stream wrapper(PHP)存在远程代码执行漏洞。远程攻击者可利用该漏洞执行任意的php代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Drupal | Drupal core | 7.x ~ 7.62 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Drupal remote code execution vulnerabilty | https://github.com/Vulnmachines/drupal-cve-2019-6339 | POC Details |
| 2 | None | https://github.com/Threekiii/Awesome-POC/blob/master/CMS%E6%BC%8F%E6%B4%9E/Drupal%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2019-6339.md | POC Details |
| 3 | https://github.com/vulhub/vulhub/blob/master/drupal/CVE-2019-6339/README.md | POC Details |
No public POC found.
Login to generate AI POC| CVE-2017-6922 | Files uploaded by anonymous users into a private file system can be accessed by other anon | |
| CVE-2019-6338 | third-party PEAR Archive_Tar library updates | |
| CVE-2017-6923 | Access bypass in Drupal 8 views |
No comments yet