Drupal SQLi (Drupalgeddon) Vulnerability: CVE-2014-3704
Description: The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
Impact: A vulnerability in this API allows an attacker to send specially crafted requests resulting in arbitrary SQL execution. Depending on the content of the requests this can lead to privilege escalation, arbitrary PHP execution or other attacks.
Mitigation: Vendor has released new version (upgrade to Drupal core 7.32)
Reference URL’s:
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3704
- https://www.drupal.org/SA-CORE-2014-005
- https://blog.sucuri.net/2016/05/drupal-sqli-drupalgeddon-attack-trend-cve-2014-3704-sa-core-2014-005.html
Recommended Posts
Press release April 2023: Situational Security Alerts from CIRT
21 Apr 2023 - Articles, English articles, News, Notice, Security Advisories & Alerts

Security Best Practices
29 Mar 2023 - Security Advisories & Alerts