Getting code execution through multiple Drupal vulnerabilities

Опубликовано: 11 Апрель 2019
на канале: Trend Zero Day Initiative
2,784
22

Demonstrating how the bugs submitted through the ZDI Targeted Initiative Program (TIP) can be combined to get code execution on an affected Drupal server. An attacker must first upload three malicious “images” to the target server and entice an authenticated site Administrator to follow a crafted link to achieve code execution.