CVE-2014-3704

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
16/10/2014
Last modified:
12/04/2025

Description

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* 7.0 (including) 7.32 (excluding)
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools