Collected research
Drupal 7 Core SQLi
SA-CORE-2014-005 - Drupal core
A flaw in Drupal 7's database abstraction API let an anonymous attacker send specially crafted requests that executed arbitrary SQL, leading on to privilege escalation and arbitrary PHP execution. Rated 25 of 25 highly critical and fixed in 7.32, it was exploited in the wild within days of the advisory.
Record
- Document
- SA-CORE-2014-005 - Drupal core
- Published by
- drupal.org
- Topic
- Injection
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of drupal.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .