Code injection in Drupal - CVE-2018-7600
Published: March 28, 2018 / Updated: February 20, 2022
Vulnerability identifier: #VU11317
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7600
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to unspecified error within multiple subsystems of Drupal installation. A remote unauthenticated attacker can execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
The vulnerability exists due to unspecified error within multiple subsystems of Drupal installation. A remote unauthenticated attacker can execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Drupal
Arch Linux
Debian Linux
Fedora
drupal7 (Debian package)
drupal7 (Alpine package)
drupal6
drupal8
Arch Linux
Debian Linux
Fedora
drupal7 (Debian package)
drupal7 (Alpine package)
drupal6
drupal8
How to mitigate CVE-2018-7600
Update to version 7.58 or 8.5.1.
drupal7 (Debian package) - update to 7.52-2+deb9u5
drupal7 (Alpine package) - update to 7.58-r0
drupal6 - update to 6.38-2.el6
drupal8 - addressed in versions 8.3.9-1.fc26, 8.4.6-3.fc27, 8.4.6-3.fc28
drupal7 (Alpine package) - update to 7.58-r0
drupal6 - update to 6.38-2.el6
drupal8 - addressed in versions 8.3.9-1.fc26, 8.4.6-3.fc27, 8.4.6-3.fc28
Links to Public Exploits and PoC-codes
- Exploit #6307 - Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit) (June 17, 2021)
- Exploit #6224 - Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC) (June 17, 2021)
- Exploit #6223 - Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (June 17, 2021)
- Exploit #5248 - scripts (A collection of scripts I've written, including automation, enumeration, exploitation, etc.) (March 30, 2021)
- Exploit #4550 - Drupalgeddon2 (CVE-2018-7600 | Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' RCE) (September 1, 2020)
- Exploit #3489 - drupalhunter (CVE-2018-7600 0-Day Exploit (cyber-warrior.org)) (July 15, 2020)
- Exploit #3044 - drupalgeddon2 (The exploit python script for CVE-2018-7600) (June 19, 2020)
- Exploit #2306 - exphub (Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340) (April 7, 2020)
- Exploit #2294 - Exploits (Containing Self Made Perl Reproducers / PoC Codes) (April 7, 2020)
- Exploit #2206 - cve5scan (5 CVE scan and exploit) (March 18, 2020)
- Exploit #2005 - CVE-2018-7600 ( (March 18, 2020)
- Exploit #2197 - cveexposer (Shell script searching for known CVE & Exploit associated with a product name/version) (March 18, 2020)
- Exploit #2042 - CVE-2018-7600-Drupal-RCE (MASS Exploiter) (March 18, 2020)
- Exploit #2033 - Drupalgeddon-Mass-Exploiter (CVE-2018-7600 and CVE-2018-7602 Mass Exploiter) (March 18, 2020)
- Exploit #1994 - Alien-Framework (Alien-Framework, it is a framework with many CVE exploits and tools to use in pen-testing.) (March 18, 2020)
- Exploit #1989 - drupal-exploit (CVE-2018-7600) (March 18, 2020)
- Exploit #1986 - drupalgeddon2 (The exploit python script for CVE-2018-7600) (March 18, 2020)
- Exploit #1985 - Drupalgeddon2 (Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)) (March 18, 2020)
- Exploit #1939 - drupal-check (Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600) (March 18, 2020)
- Exploit #1931 - CVE-2018-7600 (Exploit for Drupal 7 <= 7.57 CVE-2018-7600) (March 18, 2020)
- Exploit #1927 - drupalgeddon2 (Exploit for CVE-2018-7600.. called drupalgeddon2, ) (March 18, 2020)
- Exploit #1926 - CVE-2018-7600 (Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600)) (March 18, 2020)
- Exploit #1924 - drupalgeddon2 (MSF exploit module for Drupalgeddon 2 (CVE-2018-7600 / SA-CORE-2018-002)) (March 18, 2020)
- Exploit #186 - labs (Vulnerability Labs for security analysis) (March 18, 2020)
- Exploit #1732 - Drupal Drupalgeddon 2 Forms API Property Injection (March 18, 2020)
- Exploit #188 - CVE-EXPLOIT-DB () (March 18, 2020)
- Exploit #187 - CVE-in-Ruby (Exploits written & ported to Ruby - no Metasploit) (March 18, 2020)