Sploitus

Exploit for Immunity Canvas: DRUPAL_SERVICES_RCE

canvas · 2019-02-21

Exploit Code

MARKDOWN19 lines
## https://sploitus.com/exploit?id=DRUPAL_SERVICES_RCE
**Name**|  drupal_services_rce  
---|---  
**CVE**|  CVE-2019-6340  
**Exploit Pack**|  [CANVAS](<http://http://www.immunityinc.com/products-canvas.shtml>)  
**Description**| CVE-2019-6340  
**Notes**| CVE Name: CVE-2019-6340  
VENDOR: Drupal  
NOTES:   
An unauthenticated unserialization bug can be exploited on the RESTful Web  
Services module on the Drupal core for the following versions:  
* 7.X (Depends on enabled third party modules)  
* 8.5.X &lt; 8.5.11  
* 8.6.X &lt; 8.6.10  
  
Repeatability: Infinite  
References: https://www.drupal.org/sa-core-2019-003  
CVE Url: http://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-6340  
Date public: 22/02/2019