VDB

CVE-2014-3704

CVE-2014-3704 PUBLISHED

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

EPSS 94.37% · 100.0th percentile

Risk Scores

EPSS Score
94.37%
100.0th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSdrupal70, 7.23-1, 7.24-1

Exploit Intelligence

…and 168 more exploits

Timeline

  • CVE Published
  • Oct 16, 2014 PoC Published
  • Oct 16, 2014 PoC Published
  • Oct 16, 2014 PoC Published
  • Oct 17, 2014 PoC Published
  • Oct 18, 2014 PoC Published
  • Nov 3, 2014 PoC Published
  • Nov 3, 2014 PoC Published
  • Apr 6, 2015 PoC Published
  • May 12, 2016 PoC Published
  • Aug 23, 2016 PoC Published
  • May 11, 2017 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›