Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2018-7600-Drupalgeddon2-RCE — Educational CVE-2018-7600 exploit project combining a Python RCE PoC, isolated Docker Drupal lab, payload research, and mitigation documentation for safe vulnerable-application testing. | Kitploit
Tools/GitHubGitHub/shams-ul-mehmood/cve-2018-7600-drupalgeddon2-rce
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationPayload DevelopmentLabs & Practice
GitHub
shams-ul-mehmood/cve-2018-7600-drupalgeddon2-rce

CVE-2018-7600-Drupalgeddon2-RCE

Educational CVE-2018-7600 exploit project combining a Python RCE PoC, isolated Docker Drupal lab, payload research, and mitigation documentation for safe vulnerable-application testing.

View Repository
51 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2018-7600 (Drupalgeddon2) — Red Team Project

ITSOLERA Cybersecurity Department | Offensive Security Internship 2026


Overview

This project researches, replicates, and documents CVE-2018-7600 (Drupalgeddon2) — a Critical (CVSS 9.8) unauthenticated Remote Code Execution vulnerability in Drupal CMS, affecting versions prior to 7.58 and 8.5.1 (released March 2018).

The vulnerability exists in Drupal's Form API, which failed to sanitize user-supplied input before merging it into form element render properties — allowing attackers to inject PHP callables that the Render API would then execute.

⚠️ For educational use only. All testing must be performed exclusively against the isolated Docker lab environment. Never test on live or production systems.


Team Structure

MemberRoleDeliverables
Member 1Lab Environment & CVE VerificationDockerfile, docker-compose, SETUP.md
Member 2Exploit Developmentexploit.py framework, payloads.txt
Member 3Root Cause Analysis & Researchroot_cause_analysis.md, references.md, mitigation.md
Member 4Proof Collection & Final Reportterminal_logs.txt, screenshots, final report

Project Structure

CVE-2018-7600-Project/
│
├── README.md                           ← you are here
│
├── lab/                                ← Member 1
│   ├── Dockerfile                      ← builds Drupal 7.57 image
│   ├── docker-compose.yml              ← orchestrates all services
│   ├── entrypoint.sh                   ← DB wait + auto-config script
│   ├── SETUP.md                        ← step-by-step setup guide
│   └── config_notes.md                 ← vulnerability verification
│
├── exploit/                            ← Member 2
│   ├── exploit.py                      ← PoC Python framework
│   └── payloads.txt                    ← payload research notes
│
├── docs/                               ← Member 3
│   ├── root_cause_analysis.md          ← technical deep-dive
│   ├── references.md                   ← all sources & links
│   └── mitigation.md                   ← patch & hardening guide
│
├── proof/                              ← Member 4
│   ├── screenshots/                    ← exploitation screenshots
│   └── terminal_logs.txt               ← command output logs
│
└── report/
    └── CVE-2018-7600_Report.docx       ← Member 4: final report

Quick Start

1. Start the Lab

cd lab/
docker compose up -d --build

2. Install Drupal

Open http://localhost:8080/install.php and follow SETUP.md Step 3.

3. Verify the Target

curl -s http://localhost:8080/CHANGELOG.txt | head -3
# Expected: Drupal 7.57, 2018-02-21

4. Run the Exploit

cd ..  # project root
python exploit/exploit.py --target http://localhost:8080 --safe-mode
python exploit/exploit.py --target http://localhost:8080 --cmd "id"

5. Capture Proof

python exploit/exploit.py --target http://localhost:8080 --cmd "id" \
    --output proof/terminal_logs.txt

6. Reset Lab

cd lab/
docker compose down -v && docker compose up -d --build

CVE Summary

PropertyValue
CVE IDCVE-2018-7600
NicknameDrupalgeddon2
Vendor AdvisorySA-CORE-2018-002
CVSS v39.8 Critical
AffectedDrupal < 7.58, < 8.3.9, < 8.4.6, < 8.5.1
Fixed in7.58, 8.3.9, 8.4.6, 8.5.1
Auth RequiredNo
TypeRemote Code Execution

References

  • MITRE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7600
  • Drupal Advisory: https://www.drupal.org/sa-core-2018-002
  • ExploitDB #44449: https://www.exploit-db.com/exploits/44449
  • Rapid7: https://www.rapid7.com/db/vulnerabilities/drupal-cve-2018-7600/

ITSOLERA Red Team Internship — Summer 2026

Download Tool