Exploits from Github
547 subscribers
1 photo
644 files
3.58K links
Download Telegram
CVE-2014-3704

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

Github link:
https://github.com/joaomorenorf/CVE-2014-3704