Drupal 8.5.0, vulnerable to Drupalgeddon 2 (CVE-2018-7600): the Form API renders render arrays from request parameters whose keys start with #, so an anonymous user can make it call any PHP function.
Pas commencéDockercommit e4d489ax86_64 · aarch64Secret
Install Drupal, then exploit CVE-2018-7600 (Drupalgeddon 2) to run a command on the server without logging in.
Le brief de ce lab se trouve dans son dépôt.