Drupal SQLi (Drupalgeddon) Vulnerability: CVE-2014-3704

Description: The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

Impact: A vulnerability in this API allows an attacker to send specially crafted requests resulting in arbitrary SQL execution. Depending on the content of the requests this can lead to privilege escalation, arbitrary PHP execution or other attacks.

Mitigation: Vendor has released new version (upgrade to Drupal core 7.32)

Reference URL’s:

Share