The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T10:50:17.990Z
Reserved: 2014-05-14T00:00:00
Link: CVE-2014-3704

No data.

Status : Deferred
Published: 2014-10-16T00:55:06.653
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-3704

No data.