A construction company's website running Drupal 7.57 on PostgreSQL. That Drupal release predates the fixes for CVE-2018-7600 (Drupalgeddon 2).
Not startedDockercommit cd9dc57x86_64 · aarch64Secret
Identify the vulnerable component behind the site and exploit it to run a command on the server.
The brief for this lab lives in its repository.