Open redirect vulnerability in the Content Construction Kit (CCK) 6.x-2.x before 6.x-2.10 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destinations parameter, related to administration pages.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Content_construction_kit | Content_construction_kit_project | 6.x-2.0 (including) | 6.x-2.0 (including) |
Content_construction_kit | Content_construction_kit_project | 6.x-2.1 (including) | 6.x-2.1 (including) |
Content_construction_kit | Content_construction_kit_project | 6.x-2.2 (including) | 6.x-2.2 (including) |
Content_construction_kit | Content_construction_kit_project | 6.x-2.3 (including) | 6.x-2.3 (including) |
Content_construction_kit | Content_construction_kit_project | 6.x-2.4 (including) | 6.x-2.4 (including) |
Content_construction_kit | Content_construction_kit_project | 6.x-2.5 (including) | 6.x-2.5 (including) |
Content_construction_kit | Content_construction_kit_project | 6.x-2.6 (including) | 6.x-2.6 (including) |
Content_construction_kit | Content_construction_kit_project | 6.x-2.7 (including) | 6.x-2.7 (including) |
Content_construction_kit | Content_construction_kit_project | 6.x-2.8 (including) | 6.x-2.8 (including) |
Content_construction_kit | Content_construction_kit_project | 6.x-2.9 (including) | 6.x-2.9 (including) |