Drupal
Last updated
Was this helpful?
Last updated
Was this helpful?
All version of drupal lower than 7.58 are vulnerable to RCE.
Firstly we need to enable PHP filter
on Modules tab.
And go to Content -> +Add Content -> Article, select PHP code as Text Format and finally introduce the reverse shell on the body.
Finally clicking Preview button a reverse shell is spawned to our listener.