What happened
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
Affected versions
n/a: n/a Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
packetstormsecurity.comNVD reference2014-10-16Verifiedpacketstormsecurity.comNVD reference2014-10-16Verifiedpacketstormsecurity.comNVD reference2014-10-16Verifiedseclists.orgNVD reference2014-10-16Verifiedwww.exploit-db.comNVD reference2014-10-16Verifiedwww.exploit-db.comNVD reference2014-10-16Verifiedwww.exploit-db.comNVD reference2014-10-16Verifiedwww.exploit-db.comNVD reference2014-10-16Verifiedwww.openwall.comNVD reference2014-10-16Verifiedwww.sektioneins.deNVD reference2014-10-16Verifiedwww.sektioneins.deNVD reference2014-10-16VerifiedExploit-DB 34992Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)Claudio Viviani2014-10-17VerifiedExploit-DB 44355Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Admin Session)Stefan Horst2014-11-03VerifiedExploit-DB 34984Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (1)stopstene2014-10-16VerifiedExploit-DB 34993Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (2)Dustin Dörr2014-10-17VerifiedExploit-DB 35150Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Remote Code Execution)Stefan Horst2014-11-03VerifiedSploitusCVE-2014-3704 SQL injection in Drupal 7.5 enables remote code execution (Drupageddon).adfortunato2026-09-13T18:59:56Verifiedadfortunato/metasploitable3-pentest-writeupCVE-2014-3704 SQL injection in Drupal 7.5 enables remote code execution (Drupageddon).adfortunato2026-09-13T18:59:56VerifiedSource timeline
Discovered through Exploit-DBView source ↗
CVE record published by NVDView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.