SQL Injection (Drupal)


For this vulnerability we have to access the Drupal web inside this server 129
and to exploit this there is a hint already given for the vulnerability CVE-2014-3704
Or we can also check the exact version installed on the server by checking /CHANGELOG.txt 130
The Drupal version is 7.31 installed.
For this I found a public exploit which is SQLi written in PHP
https://www.exploit-db.com/exploits/34993/ 131
Just change the URL and run the exploit 132
Exploit successful, now we can login in drupal with admin:admin 133
Got the admin access.

~ Hack the World and Stay Noob

Twitter / Hack The Box / CTF Team / Teck_N00bs Community Telegram
