xsspresso
xsspresso
Tags/ Drupal

Drupal

3 writeups tagged with Drupal

WebMediumLinux

VHL — Tracking

Drupal 9 on Debian. Exploited an authenticated RCE vulnerability with compromised admin credentials found via enumeration.

#Drupal#RCE#Enumeration
Feb 13, 2025Virtual Hacking Labs
WebMediumLinux

VHL — CMS02

Drupal 8 on CentOS. Exploited Drupalgeddon2 (CVE-2018-7600) for unauthenticated RCE and escalated privileges via SUID binary.

#Drupal#Drupalgeddon2#CVE-2018-7600
Feb 11, 2025Virtual Hacking Labs
WebMediumWindows

HTB — Bastard

Drupal 7 authenticated RCE via Services module REST endpoint. MS15-051 kernel exploit escalates to SYSTEM.

#Drupal#RCE#REST API
May 20, 2022HackTheBox