Drupal Vulnerability: Mass Scans & Targeted Exploitation

Yesterday (October 15, 2014), a critical SQL injection vulnerability in version 7 of the popular open source content management system (CMS) Drupal was disclosed by Stefan Horst and detailed in SA-CORE-2014-005. The description of the vulnerability is rather harrowing:

http://www.volexity.com/blog/?p=83