References https://github.com/vulhub/vulhub/blob/master/drupal/CVE-2019-6339/README.md https://nvd.nist.gov/vuln/detail/CVE-2019-6339 https://www.drupal.org/sa-core-2019-002 https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/cms/Drupal-%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E-CVE-2019-6339.md https://blog.csdn.net/weixin_46411728/article/details/126521892 https://avd.aliyun.com/detail?id=AVD-2019-6339 https://www.thezdi.com/blog/2019/4/11/a-series-of-unfortunate-images-drupal-1-click-to-rce-exploit-chain-detailed https://github.com/thezdi/PoC/tree/master/Drupal https://www.cnblogs.com/f-carey/p/15935435.html https://www.cnblogs.com/paku/p/14750876.html
Related VulnerabilitiesPoCCVE-2026-10768: Drupal LocalGov Workflows < 1.6.0 - Information DisclosurePoCCVE-2026-9082: Drupal Core - Anonymous SQL Injection via PostgreSQL Entity QueryDrupal core /jsonapi/node/article SQL 注入漏洞(CVE-2026-9082)PoCdrupal-source-code-disclosure: Drupal - Source Code DisclosurePoCdrupal-directory-listing: Drupal Directory ListingPoCCVE-2021-33829: Drupal 7 CKEditor XSSCVE-2019-6340: Drupal 8 core RESTful Web Services RCEPoCCVE-2014-3704: Drupal SQL InjectionPoCCVE-2018-7600: Drupal - Remote Code ExecutionPoCCVE-2018-7602: Drupal - Remote Code ExecutionPoCCVE-2018-9205: Drupal avatar_uploader v7.x-1.0-beta8 - Local File InclusionPoCCVE-2019-6340: Drupal - Remote Code ExecutionPoCCVE-2024-45440: Drupal 11.x-dev - Full Path Disclosure