CVE-2014-3704

EXPLOITED NUCLEI LAB

Drupal < 7.32 - SQL Injection

Title source: rule

Description

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

Exploits (11)

exploitdb WORKING POC VERIFIED
by Stefan Horst · phpwebappsphp
https://www.exploit-db.com/exploits/35150
exploitdb WORKING POC VERIFIED
by Dustin Dörr · phpwebappsphp
https://www.exploit-db.com/exploits/34993
exploitdb WORKING POC VERIFIED
by Claudio Viviani · pythonwebappsphp
https://www.exploit-db.com/exploits/34992
exploitdb WORKING POC VERIFIED
by stopstene · pythonwebappsphp
https://www.exploit-db.com/exploits/34984
exploitdb WORKING POC
by Stefan Horst · phpwebappsphp
https://www.exploit-db.com/exploits/44355
nomisec WORKING POC 1 stars
by Neldeborg · remote
https://github.com/Neldeborg/Drupalgeddon-Python3
nomisec WORKING POC 1 stars
by happynote3966 · remote-auth
https://github.com/happynote3966/CVE-2014-3704
nomisec WORKING POC
by fbm31 · poc
https://github.com/fbm31/Audit-BlackBox-Web-to-Root
nomisec WORKING POC
by joaomorenorf · remote
https://github.com/joaomorenorf/CVE-2014-3704
nomisec WORKING POC
by AleDiBen · poc
https://github.com/AleDiBen/Drupalgeddon
metasploit WORKING POC EXCELLENT
by SektionEins, WhiteWinterWolf, Christian Mehlmauer, Brandon Perry · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/drupal_drupageddon.rb

Nuclei Templates (1)

Drupal SQL Injection
HIGHby princechaddha
Shodan: http.component:"drupal" || cpe:"cpe:2.3:a:drupal:drupal"

References (17)

Scores

EPSS 0.9387
EPSS Percentile 99.9%

Details

VulnCheck KEV 2021-04-12
CWE
CWE-89
Status published
Products (2)
debian/debian_linux 7.0
drupal/drupal 7.0 - 7.32
Published Oct 16, 2014
Tracked Since Feb 18, 2026