Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Drupal-Exploit-Lab — Demonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall) | Kitploit
Tools/GitHubGitHub/tea-celikik/drupal-exploit-lab
Exploit FrameworksWeb Application ExploitationWAF BypassPenetration TestingLearning & EducationLabs & Practice
GitHubtea-celikik/drupal-exploit-lab

Drupal-Exploit-Lab

Demonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall)

View Repository
6 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Drupal-Exploit-Lab

Demonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall)

Description

The project shows how the exploitation of Drupal 7.57 looks like in two different scenarios:

  1. Unprotected server → successful exploitation with Metasploit and obtaining a Meterpreter shell.
  2. Protected server → the same vulnerable version, but with protection applied (ModSecurity + OWASP CRS) → the exploitation fails.

Technologies and Tools

  • Operating Systems: Ubuntu Server 16.04 (unprotected), Ubuntu Server 22.04 (protected), Kali Linux
  • Web Server: Apache2
  • Database: MySQL / MariaDB
  • PHP: PHP 7.0 and PHP 7.4 (depending on the scenario)
  • Drupal: version 7.57
  • Security Tools: ModSecurity
  • Attack: Metasploit Framework (drupalgeddon2 module)

Authors

  • Sara Dobrevska
  • Tеа Celikiк

Note: All activities were performed in a controlled lab environment. It is prohibited to use these commands outside of isolated test environments.

Download Tool