CVE-2014-3704
Summary
| CVE | CVE-2014-3704 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-16 00:55:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Application | Drupal | Drupal | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Drupal Core <= 7.32 - SQL Injection (PHP) | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Drupal 7.X SQL Injection ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Drupal 7.31 SQL Injection ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Drupal Core <= 7.32 - SQL Injection (#2) | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Drupal Core CVE-2014-3704 SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Advisory 01/2014: Drupal - pre Auth SQL Injection Vulnerability | SektionEins GmbH | af854a3a-2127-422b-91ae-364da2661108 | www.sektioneins.de | Exploit, Patch, Third Party Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Drupal HTTP Parameter Key/Value SQL Injection ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Drupal 7.32 two weeks later - PoC | SektionEins GmbH | af854a3a-2127-422b-91ae-364da2661108 | www.sektioneins.de | Exploit, Third Party Advisory |
| osvdb.org/show/osvdb/113371 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| oss-security - Advisory 01/2014: Drupal7 - pre Auth SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Exploit, Mailing List, Patch |
| Drupal Core <= 7.32 - SQL Injection (#1) | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| SA-CORE-2014-005 - Drupal core - SQL injection | Drupal.org | af854a3a-2127-422b-91ae-364da2661108 | www.drupal.org | Patch, Vendor Advisory |
| Drupal < 7.32 Pre Auth SQL Injection | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Full Disclosure: Advisory 01/2014: Drupal7 - pre Auth SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit, Mailing List, Patch, Third Party Advisory |
| Debian -- Security Information -- DSA-3051-1 drupal7 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.