
Python-Exploit-Skript für Drupal 8 REST RCE Schwachstellen (CVE-2019-6340, CVE-2018-7600), das Remotecodeausführung auf Zielsystemen über die Endpunkte /node/1 und /user/register ermöglicht.
CVE-2019-6340 drupal8-REST-RCE (/node/1) , CVE-2018-7600 drupal8-RCE (/user/register)
Unix/Linux-Befehl - Remote-Code-Ausführung (Befehl "id")
Verwendung>
python drupal8-REST-RCE.py <dst_ip> <dst_port> (benutzerdefinierter Port)
python drupal8-REST-RCE.py <dst_ip> (Standard : 80/tcp)
[Aktualisiert!]
Skript bearbeitet für Python3-Unterstützung (2020.11.07)
Nur für Schwachstellentests an Ihrem System verwenden.