## https://sploitus.com/exploit?id=DRUPAL_NAME_SQLI_CALLBACK
**Name**| drupal_name_sqli_callback
---|---
**CVE**| CVE-2014-3704
**Exploit Pack**| [CANVAS](<http://http://www.immunityinc.com/products-canvas.shtml>)
**Description**| Drupal injection exploit
**Notes**| CVE Name: CVE-2014-3704
VENDOR: drupal.org
Notes:
This exploit tries to open a php callback to canvas by injecting php code
in Drupal's login block through the database sql injection.
Repeatability: Infinite
References: https://www.drupal.org/SA-CORE-2014-005
CVE Url: https://vulners.com/cve/CVE-2014-3704