Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3704

Опубликовано: 16 окт. 2014
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS2: 7.5

Описание

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

lucid

not-affected

precise

not-affected

trusty

DNE

trusty/esm

DNE

upstream

not-affected

Показывать по

РелизСтатусПримечание
devel

not-affected

7.32-1
esm-infra-legacy/trusty

not-affected

7.26-1ubuntu0.1
lucid

DNE

precise

released

7.12-1ubuntu0.1
trusty

released

7.26-1ubuntu0.1
trusty/esm

not-affected

7.26-1ubuntu0.1
upstream

released

7.32-1

Показывать по

EPSS

Процентиль: 100%
0.94398
Критический

7.5 High

CVSS2

Связанные уязвимости

nvd
больше 10 лет назад

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

debian
больше 10 лет назад

The expandArguments function in the database abstraction API in Drupal ...

github
около 3 лет назад

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

EPSS

Процентиль: 100%
0.94398
Критический

7.5 High

CVSS2