The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.
We have discovered 134,572 live websites that are affected by CVE-2016-7572.
Product | |
Category | Content Management System |
Vulnerable Domains | 134,572 live websites (53.57% of Drupal install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 30 versions ( 9.84% of all versions) |
![]() | 42,201 websites |
![]() | 13,939 websites |
![]() | 11,930 websites |
![]() | 10,386 websites |
![]() | 4,247 websites |
![]() | 3,940 websites |
![]() | 3,689 websites |
![]() | 3,384 websites |
![]() | 2,839 websites |
![]() | 2,503 websites |
.com | 37,022 websites |
.org | 11,560 websites |
.ru | 9,889 websites |
.de | 7,225 websites |
.fr | 4,923 websites |
.be | 4,360 websites |
.edu | 4,035 websites |
.net | 3,302 websites |
.it | 2,933 websites |
.nl | 2,762 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
******.org | ![]() | *** | |
***.org | ![]() | *,*** | |
********.gov | ![]() | *,*** | |
******.gov | ![]() | *,*** | |
***.**.gov | ![]() | *,*** | |
******.edu | ![]() | *,*** | |
***.gov | ![]() | *,*** | |
****.org | ![]() | *,*** | |
***.com | ![]() | *,*** | |
*******.com | ![]() | *,*** |
FAQ