Exploits from Github
691 subscribers
1 photo
992 files
3.96K links
Download Telegram
CVE-2014-3704

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

Github link:
https://github.com/joaomorenorf/CVE-2014-3704