Web Hack List

Other nomination

Drupal 7 Core SQLi

A flaw in Drupal 7's database abstraction API let an anonymous attacker send specially crafted requests that executed arbitrary SQL, leading on to privilege escalation and arbitrary PHP execution. Rated 25 of 25 highly critical and fixed in 7.32, it was exploited in the wild within days of the advisory.

Record

Published by
drupal.org

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of drupal.org, first published at the original source. Preserved copies are kept so the citation survives its host.