Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2017-6920

Description

Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.

POC

Reference

No PoCs from references.

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/Awrrays/FrameVul

- https://github.com/CLincat/vulcat

- https://github.com/Micr067/CMS-Hunter

- https://github.com/SecWiki/CMS-Hunter

- https://github.com/SexyBeast233/SecBooks

- https://github.com/Threekiii/Awesome-POC

- https://github.com/Threekiii/Vulhub-Reproduce

- https://github.com/XiaomingX/awesome-poc-for-red-team

- https://github.com/bakery312/Vulhub-Reproduce

- https://github.com/binfed/cms-exp

- https://github.com/cc8700619/poc

- https://github.com/copperfieldd/CMS-Hunter

- https://github.com/g1san/Agents-for-Vulnerable-Dockers-and-related-Benchmarks

- https://github.com/soosmile/cms-V

- https://github.com/superfish9/pt

- https://github.com/t0m4too/t0m4to

- https://github.com/yige666/CMS-Hunter