Drupal Core CVE-2014-3704 SQL Injection Vulnerability
BID:70595
Info
Drupal Core CVE-2014-3704 SQL Injection Vulnerability
| Bugtraq ID: | 70595 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3704 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 15 2014 12:00AM |
| Updated: | Jul 15 2015 12:14AM |
| Credit: | Stefan Horst |
| Vulnerable: |
Drupal Drupal 7.6 Drupal Drupal 7.5 Drupal Drupal 7.4 Drupal Drupal 7.3 Drupal Drupal 7.2 Drupal Drupal 7.14 Drupal Drupal 7.13 Drupal Drupal 7.12 Drupal Drupal 7.11 Drupal Drupal 7.10 Drupal Drupal 7.1 Drupal Drupal 7.0 Dev Drupal Drupal 7.0 Alpha7 Drupal Drupal 7.0 Alpha6 Drupal Drupal 7.0 Alpha5 Drupal Drupal 7.0 Alpha4 Drupal Drupal 7.0 Alpha3 Drupal Drupal 7.0 Alpha2 Drupal Drupal 7.0 Alpha1 Drupal Drupal 7.0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
Drupal Core CVE-2014-3704 SQL Injection Vulnerability
Drupal is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to execute arbitrary code, to gain elevated privileges and to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Drupal 7.x versions prior to 7.32 are vulnerable.
Drupal is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to execute arbitrary code, to gain elevated privileges and to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Drupal 7.x versions prior to 7.32 are vulnerable.
Exploit / POC
Drupal Core CVE-2014-3704 SQL Injection Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Attackers can use a browser to exploit this issue.
The following exploits are available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Attackers can use a browser to exploit this issue.
The following exploits are available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Drupal Core CVE-2014-3704 SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.