CVE-2014-3704
Currently unrated 🤨
Key Information
- Vendor
- Drupal
- Status
- Drupal
- Vendor
- CVE Published:
- 16 October 2014
Badges
👾 Exploit Exists🔴 Public PoC🟣 EPSS 97%
Summary
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
Refferences
https://www.drupal.org/SA-CORE-2014-005
x_refsource_CONFIRM
http://seclists.org/fulldisclosure/2014/Oct/75
mailing-listx_refsource_FULLDISC
http://www.securityfocus.com/archive/1/533706/100/0/threaded
mailing-listx_refsource_BUGTRAQ
https://www.sektioneins.de/en/advisories/advisory-012014-...
x_refsource_MISC
http://www.exploit-db.com/exploits/34984
exploitx_refsource_EXPLOIT-DB
http://www.exploit-db.com/exploits/35150
exploitx_refsource_EXPLOIT-DB
http://www.openwall.com/lists/oss-security/2014/10/15/23
mailing-listx_refsource_MLIST
http://secunia.com/advisories/59972
third-party-advisoryx_refsource_SECUNIA
http://packetstormsecurity.com/files/128741/Drupal-HTTP-P...
x_refsource_MISC
http://www.exploit-db.com/exploits/34992
exploitx_refsource_EXPLOIT-DB
http://www.debian.org/security/2014/dsa-3051
vendor-advisoryx_refsource_DEBIAN
http://www.securityfocus.com/bid/70595
vdb-entryx_refsource_BID
http://www.exploit-db.com/exploits/34993
exploitx_refsource_EXPLOIT-DB
http://packetstormsecurity.com/files/128721/Drupal-7.31-S...
x_refsource_MISC
http://osvdb.org/show/osvdb/113371
vdb-entryx_refsource_OSVDB
https://www.sektioneins.de/en/blog/14-11-03-drupal-sql-in...
x_refsource_MISC
http://packetstormsecurity.com/files/128720/Drupal-7.X-SQ...
x_refsource_MISC
EPSS Score
97% chance of being exploited in the next 30 days.
Timeline
- 🔴
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database2 Proof of Concept(s)