E18-0ouq1
CVSS:
6.0 (AV:N/AC:M/Au:S/C:P/I:P/A:P)
False Positive:
t
Variants:
1
Year:
2018
Description
This strike exploits a remote code execution flaw in Drupal Core. This vulnerability is due to improper handling of the HTTP parameter when a client sends http traffic to the server. A remote attacker can exploit this vulnerability by sending crafted http requests to the target server. Successful exploitation results in remote code execution.
CVE
References
MSB
BID
ExploitDB
Secunia
Security Tracker
Metasploit
ZDI
OSVDB
{}