← All CVEs

CVE-2014-3704

high · 7.5

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

7.5
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2014-10-16
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
drupaldrupal>= 7.0, < 7.32
debiandebian_linux7.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-3704