Headlines News :
Home » , , , , , » Patch/Update Drupal or Be Hacked by Highly Critical SQL Injection in Database Abstraction API

Patch/Update Drupal or Be Hacked by Highly Critical SQL Injection in Database Abstraction API

Written By Vineet Singh on Friday, 31 October 2014 | 18:49

Drupal SQL Injection - Drupal Warns of Getting Hacked Unless Patched

Millions of Drupal 7 websites might have hit by hack attack


Drupal issued an advisory on Oct 15, 2014 about vulnerability of SQL Injection in its Drupal core 7.x versions prior to 7.32.

Drupal issued its SA-CORE-2014-005 advisory, warning of a highly critical SQL injection vulnerability that is also identified as CVE-2014-3704.

The only solution is to install the latest version i.e. Drupal core 7.32.

With the issue of advisory on 15 Oct by Drupal, multiple exploits have been reported. For this they issued follow-up announcement DRUPAL-PSA-2014-003

Drupal issued very strong words in the advisory PSA-2014-003. This shows how serious the vulnerability is. Here is what they penned down:
"You should proceed under the assumption that every Drupal 7 website was compromised unless updated or patched before Oct 15th, 11pm UTC, that is 7 hours after the announcement."
There are chances that you may not be able to update to the latest Drupal version. For those users Drupal has issued a patch for Drupal's database.inc file to fix the vulnerability. Drupal also provided a help document to recover your hacked website. Take a look at their help documentation, "Your Drupal site got hacked, now what"
Share this article :

0 comments:

Speak up your mind

Tell us what you're thinking... !

Subscribe Via Email

Enter your email address:

Delivered by FeedBurner

 
UberTech News-Latest Technology News