'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2018-7600: Drupal Drupalgeddon2 Remote Code Execution Vulnerability
Severity:critical
CVE ID:CVE-2018-7600
| Descripiton:
|
Drupal is a set of free, open source content management systems developed by the Drupal community. There is a security vulnerability with multiple subsystems configured by default or universal modules in Drupal. Remote attackers can perform any code with this vulnerability. The following versions are affected: DRUPAL 7.58 Previous version, 8.4.x version before 8.4.6, 8.5.x version before 8.5.1 before 8.4.6. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.