Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

Published 15 Oct 2014Updated 16 Jun 202653 sources
CVSS 7.5 ✓ VERIFIED REFERENCE

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.