logo

Drupal Vulnerability

ID: 8abcce4a-b5f4-588d-a095-09d3679f280e

STIX ID: report--8abcce4a-b5f4-588d-a095-09d3679f280e

Feed Name: NCC Research

Threat Score
85/100

Date Published: 2026-02-26

Date Updated: 2026-08-02

...
...

This NCC Group advisory (published 16 October 2014) warns of CVE-2014-3704 — an unauthenticated SQL injection in Drupal 7 (pre-7.32) that can enable administrative takeover and server compromise. The post notes public PoCs, reports active exploitation, and supplies a Snort rule to detect attempts to modify the Drupal users table; immediate patching of Internet-facing and internal Drupal 7 instances is recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.