CVE-2018-7600

CRITICAL KEV RANSOMWARE NUCLEI LAB

Drupal Drupalgeddon 2 Forms API Property Injection

Title source: metasploit

Description

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

Exploits (63)

exploitdb WORKING POC VERIFIED
by José Ignacio Rojo · rubyremotephp
https://www.exploit-db.com/exploits/44482
exploitdb WORKING POC VERIFIED
by Vitalii Rudnykh · pythonwebappsphp
https://www.exploit-db.com/exploits/44448
exploitdb WORKING POC VERIFIED
by Hans Topo & g0tmi1k · rubywebappsphp
https://www.exploit-db.com/exploits/44449
github WRITEUP 3,480 stars
by qazbnm456 · poc
https://github.com/qazbnm456/awesome-cve-poc/tree/master/CVE-2018-7600.md
nomisec WORKING POC 593 stars
by dreadlocked · remote
https://github.com/dreadlocked/Drupalgeddon2
nomisec WORKING POC 353 stars
by a2u · remote
https://github.com/a2u/CVE-2018-7600
nomisec WORKING POC 139 stars
by pimps · remote
https://github.com/pimps/CVE-2018-7600
nomisec WORKING POC 114 stars
by g0rx · remote
https://github.com/g0rx/CVE-2018-7600-Drupal-RCE
nomisec WORKING POC 72 stars
by firefart · remote
https://github.com/firefart/CVE-2018-7600
github WRITEUP 14 stars
by xbl3 · poc
https://github.com/xbl3/awesome-cve-poc_qazbnm456/tree/master/CVE-2018-7600.md
nomisec WORKING POC 11 stars
by lorddemon · remote
https://github.com/lorddemon/drupalgeddon2
nomisec WORKING POC 8 stars
by r3dxpl0it · remote
https://github.com/r3dxpl0it/CVE-2018-7600
nomisec WORKING POC 8 stars
by rabbitmask · remote
https://github.com/rabbitmask/CVE-2018-7600-Drupal7
nomisec WORKING POC 8 stars
by zhzyker · remote
https://github.com/zhzyker/CVE-2018-7600-Drupal-POC-EXP
nomisec WORKING POC 7 stars
by thehappydinoa · remote
https://github.com/thehappydinoa/CVE-2018-7600
nomisec WORKING POC 7 stars
by dr-iman · remote
https://github.com/dr-iman/CVE-2018-7600-Drupal-0day-RCE
nomisec WORKING POC 5 stars
by jirojo2 · poc
https://github.com/jirojo2/drupalgeddon2
nomisec WORKING POC 4 stars
by ludy-dev · remote
https://github.com/ludy-dev/drupal8-REST-RCE
nomisec WORKING POC 4 stars
by shellord · remote
https://github.com/shellord/CVE-2018-7600-Drupal-RCE
nomisec WORKING POC 4 stars
by sl4cky · remote
https://github.com/sl4cky/CVE-2018-7600
nomisec WORKING POC 4 stars
by dwisiswant0 · remote
https://github.com/dwisiswant0/CVE-2018-7600
nomisec WORKING POC 3 stars
by knqyf263 · remote
https://github.com/knqyf263/CVE-2018-7600
nomisec SCANNER 3 stars
by sl4cky · remote
https://github.com/sl4cky/CVE-2018-7600-Masschecker
github WORKING POC 2 stars
by dark-vex · pythonpoc
https://github.com/dark-vex/CVE-PoC-collection/tree/master/CVE-2018-7600-Drupalgeddon2
nomisec SCANNER 2 stars
by Hestat · poc
https://github.com/Hestat/drupal-check
nomisec WORKING POC 1 stars
by muhammedkayag · remote
https://github.com/muhammedkayag/CVE-2018-7600
github WORKING POC 1 stars
by vaishakhcv · perlpoc
https://github.com/vaishakhcv/CVE-exploits/tree/master/CVE-2018-7600
nomisec WORKING POC 1 stars
by 0xAJ2K · remote
https://github.com/0xAJ2K/CVE-2018-7600
nomisec WORKING POC 1 stars
by shellord · remote
https://github.com/shellord/Drupalgeddon-Mass-Exploiter
nomisec WORKING POC 1 stars
by drugeddon · remote
https://github.com/drugeddon/drupal-exploit
nomisec WORKING POC 1 stars
by Damian972 · poc
https://github.com/Damian972/drupalgeddon-2
nomisec WORKING POC
by Meraj1312 · poc
https://github.com/Meraj1312/cve-2018-7600-drupalgeddon2-lab
gitlab WORKING POC
by SeppPenner · remote
https://gitlab.com/SeppPenner/CVE-2018-7600
gitlab WORKING POC
by thehappydinoa · remote
https://gitlab.com/thehappydinoa/CVE-2018-7600
nomisec WRITEUP
by tea-celikik · poc
https://github.com/tea-celikik/Drupal-Exploit-Lab
nomisec WORKING POC
by bixiPRO · remote
https://github.com/bixiPRO/Drupalgeddon2-CVE-2018-7600
nomisec SCANNER
by 4l13n-DN · remote
https://github.com/4l13n-DN/POC-CVE-2018-7600
nomisec WORKING POC
by M-Abid34 · remote
https://github.com/M-Abid34/CVE-2018-7600
nomisec WORKING POC
by nika0x38 · remote
https://github.com/nika0x38/CVE-2018-7600
nomisec WORKING POC
by SyedGhufranRaza · remote
https://github.com/SyedGhufranRaza/CVE-2018-7600-Remote-Code-Execution
nomisec WORKING POC
by xxxTectationxxx · remote
https://github.com/xxxTectationxxx/CVE-2018-7600
nomisec WORKING POC
by rajaabdullahnasir · poc
https://github.com/rajaabdullahnasir/CVE-2018-7600-Remote-Code-Execution
nomisec WORKING POC
by Dowonkwon · remote
https://github.com/Dowonkwon/drupal-cve-2018-7600-poc
nomisec WORKING POC
by tpdlshdmlrkfmcla · poc
https://github.com/tpdlshdmlrkfmcla/CVE-2018-7600.
github WORKING POC
by dugisan3rd · pythonpoc
https://github.com/dugisan3rd/exploit/tree/main/cve-2018-7600
nomisec WORKING POC
by raytran54 · poc
https://github.com/raytran54/CVE-2018-7600
nomisec WORKING POC
by r0lh · remote
https://github.com/r0lh/CVE-2018-7600
nomisec WORKING POC
by anldori · remote
https://github.com/anldori/CVE-2018-7600
github WORKING POC
by winterwolf32 · perlpoc
https://github.com/winterwolf32/CVE_Exploits-/tree/master/CVE-2018-7600
nomisec SCANNER
by vphnguyen · poc
https://github.com/vphnguyen/ANM_CVE-2018-7600
nomisec WORKING POC
by rafaelcaria · remote
https://github.com/rafaelcaria/drupalgeddon2-CVE-2018-7600
nomisec WRITEUP
by cved-sources · poc
https://github.com/cved-sources/cve-2018-7600
nomisec STUB
by madneal · poc
https://github.com/madneal/codeql-scanner
nomisec WORKING POC
by ruthvikvegunta · remote
https://github.com/ruthvikvegunta/Drupalgeddon2
nomisec WORKING POC
by ynsmroztas · remote
https://github.com/ynsmroztas/drupalhunter
nomisec WORKING POC
by happynote3966 · remote
https://github.com/happynote3966/CVE-2018-7600
nomisec WORKING POC
by soch4n · poc
https://github.com/soch4n/CVE-2018-7600
vulncheck_xdb WORKING POC
remote
https://github.com/user20252228/CVE-2018-7600.
vulncheck_xdb SCANNER
remote
https://github.com/SecPentester/CVE-7600-2018
vulncheck_xdb SCANNER
remote
https://github.com/1AmG0d/myDrupal
metasploit WORKING POC EXCELLENT
by Jasper Mattsson, a2u, Nixawk, FireFart, wvu · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/drupal_drupalgeddon2.rb

Nuclei Templates (1)

Drupal - Remote Code Execution
CRITICALby pikpikcu
Shodan: http.component:"drupal" || cpe:"cpe:2.3:a:drupal:drupal"

References (21)

... and 1 more

Scores

CVSS v3 9.8
EPSS 0.9449
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull drupal:8.5.0-apache
docker pull vulhub/drupal:8.5.0
docker pull drupal:7.56
+53 more repos

Details

CISA KEV 2021-11-03
VulnCheck KEV 2018-04-20
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2022-2985
Ransomware Use Confirmed
CWE
CWE-20
Status published
Products (6)
debian/debian_linux 7.0
debian/debian_linux 8.0
debian/debian_linux 9.0
drupal/core 7.0 - 7.58Packagist
drupal/drupal < 7.57
drupal/drupal 7.0 - 7.58Packagist
Published Mar 29, 2018
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026