criticalREV. 01
CVE-2014-3704Drupalgeddon — SQL Injection in Drupal's Database Layer
Drupal builds prepared statements incorrectly in its database layer, letting an unauthenticated visitor inject SQL and take the site over outright.
Read the risk
THE VITAL STATS- CVSS score
- —/ 10 No score recorded
- EPSS probability
- 100% Likelihood of exploitation
- Attack complexity
- Low Conditions needed to exploit
- Known exploited
- Not listed
- CVE published
- 2014-10-16
- Exploit published
- Yes
- Confidence
- high
- Kill chain
- initial access
- MITRE ATT&CK
- T1190
- Severity
- critical
Attacker needsNetwork access to the site
Fixed inDrupal 7.32
Behind the card
5 REFERENCES- 01CVE recordNVD recordnvd.nist.gov
- 02Vendor advisorydrupal.orgdrupal.org
- 03Exploitpacketstormsecurity.compacketstormsecurity.com
- 04Exploitpacketstormsecurity.compacketstormsecurity.com
- 05Exploitpacketstormsecurity.compacketstormsecurity.com
Field-level provenanceTRACE THE SOURCES +
Which source supports each field, when it was retrieved, and who extracted it.
| Fields | Source | Retrieved | Extractor | Confidence |
|---|---|---|---|---|
| exploitation.attack_complexity, exploitation.exploit_available, references, published_at | nvd.nist.gov | 2026-08-07 | scrty-crds-pipeline/0.1 | high |
| epss | api.first.org | 2026-08-07 | scrty-crds-pipeline/0.1 | high |
| title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisites | nvd.nist.gov | 2026-08-07 | claude-code | high |
Printing history
THE RECORD- r1Initial base card
First printing. This card has not been reprinted since publication.