Web Hack List

Collected research

Drupal 7 Core SQLi

SA-CORE-2014-005 - Drupal core

A flaw in Drupal 7's database abstraction API let an anonymous attacker send specially crafted requests that executed arbitrary SQL, leading on to privilege escalation and arbitrary PHP execution. Rated 25 of 25 highly critical and fixed in 7.32, it was exploited in the wild within days of the advisory.

Record

Document
SA-CORE-2014-005 - Drupal core
Published by
drupal.org
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of drupal.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .