Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-7600

KEV · Ransomware EPSS 94.49% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2018-7600

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Drupal 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。 Drupal中带有默认或通用模块配置的多个子系统存在安全漏洞。远程攻击者可利用该漏洞执行任意代码。以下版本受到影响:Drupal 7.58之前版本,8.3.9之前的8.x版本,8.4.6之前的8.4.x版本,8.5.1之前的8.5.x版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 -

II. Public POCs for CVE-2018-7600

#POC DescriptionSource LinkShenlong Link
1CVE-2018-7600 Drupal RCEhttps://github.com/g0rx/CVE-2018-7600-Drupal-RCEPOC Details
2💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002https://github.com/a2u/CVE-2018-7600POC Details
3Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)https://github.com/dreadlocked/Drupalgeddon2POC Details
4CVE-2018-7600 (Drupal)https://github.com/knqyf263/CVE-2018-7600POC Details
5Drupal 0day Remote PHP Code Execution (Perl)https://github.com/dr-iman/CVE-2018-7600-Drupal-0day-RCEPOC Details
6MSF exploit module for Drupalgeddon 2 (CVE-2018-7600 / SA-CORE-2018-002)https://github.com/jirojo2/drupalgeddon2POC Details
7PoC for CVE-2018-7600 Drupal SA-CORE-2018-002 (Drupalgeddon 2).https://github.com/dwisiswant0/CVE-2018-7600POC Details
8Proof-of-Concept for Drupal CVE-2018-7600 / SA-CORE-2018-002https://github.com/thehappydinoa/CVE-2018-7600POC Details
9Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600)https://github.com/sl4cky/CVE-2018-7600POC Details
10Tool to check for CVE-2018-7600 vulnerability on several URLShttps://github.com/sl4cky/CVE-2018-7600-MasscheckerPOC Details
11CVE-2018-7600 - Drupal 7.x RCEhttps://github.com/firefart/CVE-2018-7600POC Details
12Exploit for Drupal 7 <= 7.57 CVE-2018-7600https://github.com/pimps/CVE-2018-7600POC Details
13Exploit for CVE-2018-7600.. called drupalgeddon2, https://github.com/lorddemon/drupalgeddon2POC Details
14Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600https://github.com/Hestat/drupal-checkPOC Details
15Vuln checker for Drupal v7.x + v8.x (CVE-2018-7600 / SA-CORE-2018-002)https://github.com/Damian972/drupalgeddon-2POC Details
16Nonehttps://github.com/jyo-zi/CVE-2018-7600POC Details
17Nonehttps://github.com/happynote3966/CVE-2018-7600POC Details
18MASS Exploiterhttps://github.com/shellord/CVE-2018-7600-Drupal-RCEPOC Details
19CVE-2018-7600 POC (Drupal RCE)https://github.com/r3dxpl0it/CVE-2018-7600POC Details
20cve-2018-7600https://github.com/cved-sources/cve-2018-7600POC Details
21The exploit python script for CVE-2018-7600https://github.com/madneal/codeql-scannerPOC Details
22CVE-2018-7600https://github.com/drugeddon/drupal-exploitPOC Details
23CVE-2018-7600 and CVE-2018-7602 Mass Exploiterhttps://github.com/shellord/Drupalgeddon-Mass-ExploiterPOC Details
24CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本https://github.com/zhzyker/CVE-2018-7600-Drupal-POC-EXPPOC Details
25CVE-2018-7600【Drupal7】批量扫描工具。https://github.com/rabbitmask/CVE-2018-7600-Drupal7POC Details
26CVE-2018-7600 0-Day Exploit (cyber-warrior.org)https://github.com/ynsmroztas/drupalhunterPOC Details
27CVE-2018-7600 | Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' RCEhttps://github.com/ruthvikvegunta/Drupalgeddon2POC Details
28Drupal 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.https://github.com/0xAJ2K/CVE-2018-7600POC Details
29Nonehttps://github.com/rafaelcaria/drupalgeddon2-CVE-2018-7600POC Details
30Detect with python and tracking IPhttps://github.com/vphnguyen/ANM_CVE-2018-7600POC Details
31Nonehttps://github.com/0xConstant/CVE-2018-7600POC Details
32Nonehttps://github.com/anldori/CVE-2018-7600POC Details
33Drupal CVE-2018-7600 RCE Pseudo-Shell PoChttps://github.com/r0lh/CVE-2018-7600POC Details
34CVE-2018-7600 漏洞验证和利用https://github.com/killeveee/CVE-2018-7600POC Details
35Nonehttps://github.com/soch4n/CVE-2018-7600POC Details
36Nonehttps://github.com/raytran54/CVE-2018-7600POC Details
37Nonehttps://github.com/banomaly/CVE-2018-7600POC Details
38CVE-2018-7600.https://github.com/mr-won/CVE-2018-7600.POC Details
39Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-7600.yamlPOC Details
40Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/CMS%E6%BC%8F%E6%B4%9E/Drupal%20Drupalgeddon%202%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2018-7600.mdPOC Details
41https://github.com/vulhub/vulhub/blob/master/drupal/CVE-2018-7600/README.mdPOC Details
42CVE-2018-7600.https://github.com/user20252228/CVE-2018-7600.POC Details
43CVE-2018-7600.https://github.com/tpdlshdmlrkfmcla/CVE-2018-7600.POC Details
44Nonehttps://github.com/Dowonkwon/drupal-cve-2018-7600-pocPOC Details
45For Home Lab and Educational Purpose only not intended for any Harmful intenstions purely for educational purposehttps://github.com/M-Abid34/CVE-2018-7600POC Details
46This repository contains a completely original and self-developed Proof-of-Concept (PoC) for CVE-2018-7600, also known as Drupalgeddon 2 — a critical remote code execution vulnerability affecting Drupal 7 and 8 core versions.https://github.com/rajaabdullahnasir/CVE-2018-7600-Remote-Code-ExecutionPOC Details
47Program python untuk melakukan RCE pada drupal versi 7.56https://github.com/xxxTectationxxx/CVE-2018-7600POC Details
48PoC of CVE-2018-7600https://github.com/muhammedkayag/CVE-2018-7600POC Details
49This repository showcases a fully self-developed Proof-of-Concept (PoC) for CVE-2018-7600, widely known as Drupalgeddon 2. This critical vulnerability in Drupal 7 and 8 core enables remote code execution (RCE), and the PoC demonstrates its exploitation in a clear and educational manner.https://github.com/SyedGhufranRaza/CVE-2018-7600-Remote-Code-ExecutionPOC Details
50A Rust implementation of the CVE-2018-7600 exploit targeting vulnerable Drupal 7 installations (<= 7.57)https://github.com/nika0x38/CVE-2018-7600POC Details
51Demonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall) https://github.com/tea-celikik/Drupal-Exploit-LabPOC Details
52Drupal vulnerable a CVE-2018-7600https://github.com/4l13n-DN/POC-CVE-2018-7600POC Details
53Nonehttps://github.com/bixiPRO/Drupalgeddon2-CVE-2018-7600POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-7600

登录查看更多情报信息。

Same Patch Batch · n/a · 2018-03-29 · 26 CVEs total

CVE-2015-2002ESRI ArcGis Runtime SDK for Android 安全漏洞
CVE-2017-16873Hashicorp vagrant-vmware-fusion 安全漏洞
CVE-2017-16839Hashicorp vagrant-vmware-fusion 安全漏洞
CVE-2017-16512Hashicorp vagrant-vmware-fusion 安全漏洞
CVE-2016-6658Pivotal cf-release 安全漏洞
CVE-2016-0898Pivotal Software MySQL for PCF 信息泄露漏洞
CVE-2017-5947多款OnePlus One产品OxygenOS 安全漏洞
CVE-2015-4953IBM BigFix Remote Control 加密问题漏洞
CVE-2015-4952IBM Endpoint Manager for Remote Control on-demand插件安全漏洞
CVE-2015-2020MyScript SDK for Android 安全漏洞
CVE-2015-2009IBM QRadar SIEM 跨站请求伪造漏洞
CVE-2015-2004GraceNote GNSDK for Android 安全漏洞
CVE-2015-2003PJSIP PJSUA2 SDK for Android 安全漏洞
CVE-2018-9120Crea8social 跨站脚本漏洞
CVE-2015-2001MetaIO SDK for Android 安全漏洞
CVE-2015-2000Jumio SDK for Android 安全漏洞
CVE-2014-6604WordPress Subscribe2插件跨站脚本漏洞
CVE-2014-5170Drupal Storage API模块安全漏洞
CVE-2014-5028Beanbag Review Board 安全漏洞
CVE-2018-9031TNLSoftSolutions Sentry 安全漏洞

Showing top 20 of 26 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2018-7600

No comments yet


Leave a comment