Drupal Database login action api SQL Injection Vulnerability
Release date:
Updated on:
Affected Systems:
Drupal 7.x
Description:
CVE (CAN) ID: CVE-2014-3704
Drupal is an open-source Content Management Framework (CMF) written in PHP. It consists of a Content Management System (CMS) and a PHP development Framework.
Some inputs received by the Database summary API in versions earlier than Drupal 7.32 are not in the "database: expandArguments ()" method (supported des/database/Database. (inc.
<* Source: Stefan Horst
*>
Suggestion:
Vendor patch:
Drupal
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://drupal.org/node/
SA-CORE-2014-005:
Https://www.drupal.org/SA-CORE-2014-005
Stefan Horst:
Https://www.sektioneins.de/advisories/advisory-012014-drupal-pre-auth-sql-injection-vulnerability.html
Install Drupal 7 in Ubuntu 14.04 LTS
Drupal details: click here
Drupal: click here
This article permanently updates the link address: