**Fuzz `/node/$` where `$` is a number** \(from 1 to 500 for example\).
You could find **hidden pages** \(test, dev\) which are not referenced by the search engines.
## Code execution inside Drupal with admin creds
You need the **plugin php to be installed** \(check it accessing to _/modules/php_ and if it returns a **403** then, **exists**, if **not found**, then the **plugin php isn't installed**\)
Go to _Modules_ -> \(**Check**\) _PHP Filter_ ->_Save configuration_
![](../../.gitbook/assets/image%20%28247%29.png)
Then click on _Add content_ -> Select _Basic Page_ or _Article -_> Write _php shellcode on the body_ -> Select _PHP code_ in _Text format_ -> Select _Preview_