CVE-2014-3704: SQL Injection
Published Oct 16, 2014
·Updated
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
Affected Software
2 affected components
Drupal Drupal>=7.0<7.32
Debian Debian Linux=7.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Oct 16, 2014
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3704?
CVE-2014-3704 has a critical severity rating due to its potential for SQL injection attacks.
2
How do I fix CVE-2014-3704?
To remediate CVE-2014-3704, upgrade Drupal to version 7.32 or later.
3
Which versions of Drupal are affected by CVE-2014-3704?
CVE-2014-3704 affects Drupal core versions prior to 7.32.
4
Can CVE-2014-3704 be exploited remotely?
Yes, CVE-2014-3704 can be exploited by remote attackers through crafted SQL inputs.
5
What are the potential impacts of CVE-2014-3704?
The potential impacts of CVE-2014-3704 include unauthorized data access and possible database manipulation.