Hello Evebody,

For security purpose and to follow Drupal recommendation we make an update from Drupal version 7.56 to version 7.59.

Security advisories : https://www.drupal.org/SA-CORE-2018-004 ( If you are running 7.x, upgrade to Drupal 7.59 )

Problem is that after update performing we make a vulnerability test with Drupalgeddon2 ruby file and it woks well like on Drupal 7.56 version.

So I want to know if Drupal 7.59 doesn't resolve this issue (Remote Code Execution - SA-CORE-2018-004).

What can I do in my case to solve it ?

It necessary to perform an upgrade to Drupal 8.5 version to solve this issue ?

Thank you for your assistance.

Comments

vm’s picture

follow the links in the PSA regarding already compromised sites.