VDB
CVE-2014-3704
CVE-2014-3704
PUBLISHED
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
EPSS 99.97% · 100.0th percentile
Risk Scores
EPSS Score
99.97%
100.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:14.04:LTS | drupal7 | 0, 7.23-1, 7.24-1 |
Timeline
- CVE Published
- Oct 16, 2014 PoC Published
- Oct 16, 2014 PoC Published
- Oct 16, 2014 PoC Published
- Oct 17, 2014 PoC Published
- Oct 18, 2014 PoC Published
- Nov 3, 2014 PoC Published
- Nov 3, 2014 PoC Published
- Apr 6, 2015 PoC Published
- May 12, 2016 PoC Published
- Aug 23, 2016 PoC Published
- May 11, 2017 PoC Published
References
- https://ubuntu.com/security/CVE-2014-3704 third-party-advisory
- https://www.sektioneins.de/en/advisories/advisory-012014-drupal-pre-auth-sql-injection-vulnerability.html third-party-advisory
- https://www.drupal.org/SA-CORE-2014-005 third-party-advisory
- http://www.openwall.com/lists/oss-security/2014/10/15/23 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2014-3704 third-party-advisory
- Vulnérabilité dans Drupal advisory