Lucene search

K
f5F5F5:K15782
HistoryNov 03, 2014 - 12:00 a.m.

K15782 : SQL injection vulnerability CVE-2014-3704

2014-11-0300:00:00
my.f5.com
188

8.2 High

AI Score

Confidence

High

0.975 High

EPSS

Percentile

100.0%

Security Advisory Description

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
(
CVE-2014-3704
)
Impact
None. No F5 products are affected by this vulnerability.