Loading
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
Use CWE-89, Drupal vendor hub and Drupal product page to widen CVE-2014-3704 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-55638, CVE-2024-55637 and CVE-2024-55636 for nearby disclosures in the same product family.