🔙 목록으로 돌아가기

CVE-2018-7602: Drupal - Remote Code Execution

TitleDrupal - Remote Code Execution
Authorprincechaddha
SeverityCritical
ImpactRemote attackers can execute arbitrary code on the affected Drupal installations.
RemediationUpgrade to Drupal 7.58, 8.3.9, 8.4.6, or 8.5.1 or apply the necessary patches provided by Drupal.
CVSS Score9.8
EPSS Score0.94337
CVE IDCVE-2018-7602
Shodan Queryhttp.component:"drupal"cpe:"cpe:2.3:a:drupal:drupal"
Tags cve cve2018 drupal authenticated kev vulhub edb vkev vuln

🔍 Vulnerability Description

Drupal 7.x and 8.x contain a remote code execution vulnerability that exists within multiple subsystems. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

🌐 HTTP Request

POST /?q=user%2Flogin HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36
Connection: close
Content-Length: 52
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

form_id=user_login&name=MtClTB&pass=PVsIbN&op=Log+in

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-7602.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-7602.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A