Drupal 8.6.9 RCE Exploiting with Python (CVE-2019-6340/SA-CORE-2019-003)

Опубликовано: 25 Февраль 2019
на канале: DevDungeon
9,393
94

Today, Ronald Eddings from SecDevOps.ai joins me to demonstrate a recently reported highly critical vulnerability on Drupal 8. On February 20, 2019 the REST web services in Drupal 8.6.9 were reported as vulnerable to remote code execution via shell injection done through deserialized data passed to the REST API. We demonstrate how the vulnerability works.

https://www.ambionics.io/blog/drupal8...
https://www.drupal.org/sa-core-2019-003
https://www.drupal.org/project/drupal...
https://github.com/g0rx/Drupal-SA-COR...
https://github.com/DevDungeon/CVE-201...