CVE-2014-3704
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
- Affected products
- Drupal
- Drupal
- < 7.32
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2014-10-16
CVE-2014-3704 at NVD
27 known exploits for CVE-2014-3704
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for SQL Injection in Drupal
CVE-2014-3704
CVE-2014-3704
Drupalgeddon-Python3
Audit-BlackBox-Web-to-Root
Exploit for SQL Injection in Drupal
Drupal 7.0 < 7.31 - Drupalgeddon SQL Injection (Admin Session) Exploit
Drupal core 7.x SQL Injection
Drupal Core <= 7.32 - SQL Injection (#2)
Drupal Core <= 7.32 - SQL Injection (PHP)
Drupal < 7.32 Pre Auth SQL Injection Vulnerability
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Admin Session)
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Remote Code Execution)
Drupal HTTP Parameter Key/Value SQL Injection Vulnerability
Drupal HTTP Parameter Key/Value SQL Injection
Drupal 7.31 CORE pre Auth SQL Injection Vulnerability
Drupal 7.0 7.31 - Drupalgeddon SQL Injection (Add Admin User)
Drupal 7.0 7.31 - Drupalgeddon SQL Injection (PoC) (Reset Password) (2)
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (2)
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)
Drupal 7.x SQL Injection
Drupal Core 7.32 SQL Injection
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (1)
Drupal 7.X SQL Injection
Immunity Canvas: DRUPAL_NAME_SQLI_CALLBACK
Immunity Canvas: DRUPAL_NAME_SQLI
Drupal HTTP Parameter Key/Value SQL Injection