Follow up on Drupal SA-2014-005, SQL Injection | Drupal.org
the PSA also resulted in a large volume of press coverage – in fact much more coverage than the original disclosure of the vulnerability on October 15th. Not surprisingly, the general tone of the press coverage was quite negative. Unfortunately, some of the coverage was also inaccurate which we’d like to address here as well as provide additional context regarding our security processes. While we don’t know the total number of Drupal sites affected, the number is not near 12 million as stated in several publications.