Sploitus

CVE-2014-3704

27 known exploits for CVE-2014-3704

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

Affected products
Drupal
Drupal
< 7.32
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
100.0% (100th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2014-10-16
CVE-2014-3704 at NVD
Authoritative description, scoring and affected products

27 known exploits for CVE-2014-3704

Proof-of-concept code and exploit modules indexed by Sploitus

Exploit for SQL Injection in Drupal
2026-09-13 adfortunatoGITHUB
CVE-2014-3704
2026-09-13 KitPloitKITPLOIT
CVE-2014-3704
2026-09-13 KitPloitKITPLOIT
Drupalgeddon-Python3
2026-09-12 KitPloitKITPLOIT
Audit-BlackBox-Web-to-Root
2026-09-09 KitPloitKITPLOIT
Exploit for SQL Injection in Drupal
2020-10-06 enaGITEE
Drupal 7.0 < 7.31 - Drupalgeddon SQL Injection (Admin Session) Exploit
2018-03-29 Stefan HorstZDTPHP
Drupal core 7.x SQL Injection
2015-04-22 Dsquare SecurityD2
Drupal Core <= 7.32 - SQL Injection (#2)
2014-11-13 RootSEEBUGPython
Drupal Core <= 7.32 - SQL Injection (PHP)
2014-11-13 RootSEEBUG
Drupal < 7.32 Pre Auth SQL Injection Vulnerability
2014-11-04 Stefan HorstZDTPHP
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Admin Session)
2014-11-03 Stefan HorstEXPLOITDBPHP
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Remote Code Execution)
2014-11-03 Stefan HorstEXPLOITDBPHP
Drupal HTTP Parameter Key/Value SQL Injection Vulnerability
2014-10-18 metasploitZDTRuby
Drupal HTTP Parameter Key/Value SQL Injection
2014-10-18 Brandon PerryPACKETSTORMRuby
Drupal 7.31 CORE pre Auth SQL Injection Vulnerability
2014-10-17 Stefan HorstZDT
Drupal 7.0 7.31 - Drupalgeddon SQL Injection (Add Admin User)
2014-10-17 Claudio VivianiEXPLOITPACKPython
Drupal 7.0 7.31 - Drupalgeddon SQL Injection (PoC) (Reset Password) (2)
2014-10-17 Dustin DörrEXPLOITPACKPHP
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (2)
2014-10-17 Dustin DörrEXPLOITDBPHP
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)
2014-10-17 Claudio VivianiEXPLOITDBPython
Drupal 7.x SQL Injection
2014-10-17 Milan KragujevicPACKETSTORMPHP
Drupal Core 7.32 SQL Injection
2014-10-17 fyukyukPACKETSTORMPython
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (1)
2014-10-16 stopsteneEXPLOITDBPython
Drupal 7.X SQL Injection
2014-10-16 Claudio VivianiPACKETSTORMPython
Immunity Canvas: DRUPAL_NAME_SQLI_CALLBACK
2014-10-15 Immunity CanvasCANVAS
Immunity Canvas: DRUPAL_NAME_SQLI
2014-10-15 Immunity CanvasCANVAS
Drupal HTTP Parameter Key/Value SQL Injection
2014-10-15 SektionEins, WhiteWinterWolf, Christian Mehlmauer <FireFart@gmail.com>, Brandon PerryMETASPLOITRuby