CVE-2018-7600

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an...

Basic Information

CVE State
PUBLISHED
Reserved Date
March 01, 2018
Published Date
March 29, 2018
Last Updated
February 07, 2025
Vendor
n/a
Product
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1
Description
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

CVSS Scores

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2021-11-03 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2021-10-27 03:09:48 UTC) Source
Used in Malware
Yes (added 2021-11-03 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2021-11-03 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

drupal_drupalgeddon2

Type: metasploit • Created: Unknown

Metasploit module for CVE-2018-7600

user20252228/CVE-2018-7600.

Type: github • Created: 2025-03-19 05:28:51 UTC • Stars: 0

CVE-2018-7600.

raytran54/CVE-2018-7600

Type: github • Created: 2024-06-12 06:40:17 UTC • Stars: 0

killeveee/CVE-2018-7600

Type: github • Created: 2024-02-01 05:30:19 UTC • Stars: 1

CVE-2018-7600 漏洞验证和利用

r0lh/CVE-2018-7600

Type: github • Created: 2022-12-17 11:11:47 UTC • Stars: 0

Drupal CVE-2018-7600 RCE Pseudo-Shell PoC

anldori/CVE-2018-7600

Type: github • Created: 2022-04-25 08:46:00 UTC • Stars: 0

vphnguyen/ANM_CVE-2018-7600

Type: github • Created: 2021-11-26 03:25:50 UTC • Stars: 0

Detect with python and tracking IP

rafaelcaria/drupalgeddon2-CVE-2018-7600

Type: github • Created: 2021-10-27 03:09:48 UTC • Stars: 0

0xAJ2K/CVE-2018-7600

Type: github • Created: 2021-06-05 09:49:56 UTC • Stars: 1

Drupal 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

rabbitmask/CVE-2018-7600-Drupal7

Type: github • Created: 2020-04-12 07:37:14 UTC • Stars: 8

CVE-2018-7600【Drupal7】批量扫描工具。

zhzyker/CVE-2018-7600-Drupal-POC-EXP

Type: github • Created: 2020-04-07 06:54:13 UTC • Stars: 7

CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本

r3dxpl0it/CVE-2018-7600

Type: github • Created: 2018-10-23 21:47:59 UTC • Stars: 8

CVE-2018-7600 POC (Drupal RCE)

shellord/CVE-2018-7600-Drupal-RCE

Type: github • Created: 2018-10-02 04:25:02 UTC • Stars: 4

MASS Exploiter

happynote3966/CVE-2018-7600

Type: github • Created: 2018-07-12 01:12:44 UTC • Stars: 0

pimps/CVE-2018-7600

Type: github • Created: 2018-04-17 15:38:15 UTC • Stars: 133

Exploit for Drupal 7 <= 7.57 CVE-2018-7600

firefart/CVE-2018-7600

Type: github • Created: 2018-04-16 20:16:21 UTC • Stars: 71

CVE-2018-7600 - Drupal 7.x RCE

sl4cky/CVE-2018-7600-Masschecker

Type: github • Created: 2018-04-15 14:56:35 UTC • Stars: 3

Tool to check for CVE-2018-7600 vulnerability on several URLS

sl4cky/CVE-2018-7600

Type: github • Created: 2018-04-15 12:01:41 UTC • Stars: 4

Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600)

thehappydinoa/CVE-2018-7600

Type: github • Created: 2018-04-15 02:21:59 UTC • Stars: 7

Proof-of-Concept for Drupal CVE-2018-7600 / SA-CORE-2018-002

dwisiswant0/CVE-2018-7600

Type: github • Created: 2018-04-14 18:26:26 UTC • Stars: 4

PoC for CVE-2018-7600 Drupal SA-CORE-2018-002 (Drupalgeddon 2).

dr-iman/CVE-2018-7600-Drupal-0day-RCE

Type: github • Created: 2018-04-14 09:02:54 UTC • Stars: 8

Drupal 0day Remote PHP Code Execution (Perl)

knqyf263/CVE-2018-7600

Type: github • Created: 2018-04-13 10:04:36 UTC • Stars: 3

CVE-2018-7600 (Drupal)

a2u/CVE-2018-7600

Type: github • Created: 2018-03-30 14:23:18 UTC • Stars: 351

💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002

g0rx/CVE-2018-7600-Drupal-RCE

Type: github • Created: 2018-03-30 08:52:54 UTC • Stars: 116

CVE-2018-7600 Drupal RCE