CVE Vulnerabilities

CVE-2016-3164

Published: Apr 12, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.

Affected Software

NameVendorStart VersionEnd Version
DrupalDrupal6.0 (including)6.0 (including)
DrupalDrupal6.0-beta1 (including)6.0-beta1 (including)
DrupalDrupal6.0-beta2 (including)6.0-beta2 (including)
DrupalDrupal6.0-beta3 (including)6.0-beta3 (including)
DrupalDrupal6.0-beta4 (including)6.0-beta4 (including)
DrupalDrupal6.0-dev (including)6.0-dev (including)
DrupalDrupal6.0-rc1 (including)6.0-rc1 (including)
DrupalDrupal6.0-rc2 (including)6.0-rc2 (including)
DrupalDrupal6.0-rc3 (including)6.0-rc3 (including)
DrupalDrupal6.0-rc4 (including)6.0-rc4 (including)
DrupalDrupal6.1 (including)6.1 (including)
DrupalDrupal6.2 (including)6.2 (including)
DrupalDrupal6.3 (including)6.3 (including)
DrupalDrupal6.4 (including)6.4 (including)
DrupalDrupal6.5 (including)6.5 (including)
DrupalDrupal6.6 (including)6.6 (including)
DrupalDrupal6.7 (including)6.7 (including)
DrupalDrupal6.8 (including)6.8 (including)
DrupalDrupal6.9 (including)6.9 (including)
DrupalDrupal6.10 (including)6.10 (including)
DrupalDrupal6.11 (including)6.11 (including)
DrupalDrupal6.12 (including)6.12 (including)
DrupalDrupal6.13 (including)6.13 (including)
DrupalDrupal6.14 (including)6.14 (including)
DrupalDrupal6.15 (including)6.15 (including)
DrupalDrupal6.16 (including)6.16 (including)
DrupalDrupal6.17 (including)6.17 (including)
DrupalDrupal6.18 (including)6.18 (including)
DrupalDrupal6.19 (including)6.19 (including)
DrupalDrupal6.20 (including)6.20 (including)
DrupalDrupal6.21 (including)6.21 (including)
DrupalDrupal6.22 (including)6.22 (including)
DrupalDrupal6.23 (including)6.23 (including)
DrupalDrupal6.24 (including)6.24 (including)
DrupalDrupal6.25 (including)6.25 (including)
DrupalDrupal6.26 (including)6.26 (including)
DrupalDrupal6.27 (including)6.27 (including)
DrupalDrupal6.28 (including)6.28 (including)
DrupalDrupal6.29 (including)6.29 (including)
DrupalDrupal6.30 (including)6.30 (including)
DrupalDrupal6.31 (including)6.31 (including)
DrupalDrupal6.32 (including)6.32 (including)
DrupalDrupal6.33 (including)6.33 (including)
DrupalDrupal6.34 (including)6.34 (including)
DrupalDrupal6.35 (including)6.35 (including)
DrupalDrupal6.36 (including)6.36 (including)
DrupalDrupal6.37 (including)6.37 (including)
DrupalDrupal7.0 (including)7.0 (including)
DrupalDrupal7.0-alpha1 (including)7.0-alpha1 (including)
DrupalDrupal7.0-alpha2 (including)7.0-alpha2 (including)
DrupalDrupal7.0-alpha3 (including)7.0-alpha3 (including)
DrupalDrupal7.0-alpha4 (including)7.0-alpha4 (including)
DrupalDrupal7.0-alpha5 (including)7.0-alpha5 (including)
DrupalDrupal7.0-alpha6 (including)7.0-alpha6 (including)
DrupalDrupal7.0-alpha7 (including)7.0-alpha7 (including)
DrupalDrupal7.0-beta1 (including)7.0-beta1 (including)
DrupalDrupal7.0-beta2 (including)7.0-beta2 (including)
DrupalDrupal7.0-beta3 (including)7.0-beta3 (including)
DrupalDrupal7.0-dev (including)7.0-dev (including)
DrupalDrupal7.0-rc1 (including)7.0-rc1 (including)
DrupalDrupal7.0-rc2 (including)7.0-rc2 (including)
DrupalDrupal7.0-rc3 (including)7.0-rc3 (including)
DrupalDrupal7.0-rc4 (including)7.0-rc4 (including)
DrupalDrupal7.1 (including)7.1 (including)
DrupalDrupal7.2 (including)7.2 (including)
DrupalDrupal7.3 (including)7.3 (including)
DrupalDrupal7.4 (including)7.4 (including)
DrupalDrupal7.5 (including)7.5 (including)
DrupalDrupal7.6 (including)7.6 (including)
DrupalDrupal7.7 (including)7.7 (including)
DrupalDrupal7.8 (including)7.8 (including)
DrupalDrupal7.9 (including)7.9 (including)
DrupalDrupal7.10 (including)7.10 (including)
DrupalDrupal7.11 (including)7.11 (including)
DrupalDrupal7.12 (including)7.12 (including)
DrupalDrupal7.13 (including)7.13 (including)
DrupalDrupal7.14 (including)7.14 (including)
DrupalDrupal7.15 (including)7.15 (including)
DrupalDrupal7.16 (including)7.16 (including)
DrupalDrupal7.17 (including)7.17 (including)
DrupalDrupal7.18 (including)7.18 (including)
DrupalDrupal7.19 (including)7.19 (including)
DrupalDrupal7.20 (including)7.20 (including)
DrupalDrupal7.21 (including)7.21 (including)
DrupalDrupal7.22 (including)7.22 (including)
DrupalDrupal7.23 (including)7.23 (including)
DrupalDrupal7.24 (including)7.24 (including)
DrupalDrupal7.25 (including)7.25 (including)
DrupalDrupal7.26 (including)7.26 (including)
DrupalDrupal7.27 (including)7.27 (including)
DrupalDrupal7.28 (including)7.28 (including)
DrupalDrupal7.29 (including)7.29 (including)
DrupalDrupal7.30 (including)7.30 (including)
DrupalDrupal7.31 (including)7.31 (including)
DrupalDrupal7.32 (including)7.32 (including)
DrupalDrupal7.33 (including)7.33 (including)
DrupalDrupal7.34 (including)7.34 (including)
DrupalDrupal7.35 (including)7.35 (including)
DrupalDrupal7.36 (including)7.36 (including)
DrupalDrupal7.37 (including)7.37 (including)
DrupalDrupal7.38 (including)7.38 (including)
DrupalDrupal7.40 (including)7.40 (including)
DrupalDrupal7.41 (including)7.41 (including)
DrupalDrupal7.42 (including)7.42 (including)
DrupalDrupal7.x-dev (including)7.x-dev (including)
DrupalDrupal8.0.0 (including)8.0.0 (including)
DrupalDrupal8.0.0-alpha10 (including)8.0.0-alpha10 (including)
DrupalDrupal8.0.0-alpha11 (including)8.0.0-alpha11 (including)
DrupalDrupal8.0.0-alpha12 (including)8.0.0-alpha12 (including)
DrupalDrupal8.0.0-alpha13 (including)8.0.0-alpha13 (including)
DrupalDrupal8.0.0-alpha14 (including)8.0.0-alpha14 (including)
DrupalDrupal8.0.0-alpha15 (including)8.0.0-alpha15 (including)
DrupalDrupal8.0.0-alpha2 (including)8.0.0-alpha2 (including)
DrupalDrupal8.0.0-alpha3 (including)8.0.0-alpha3 (including)
DrupalDrupal8.0.0-alpha4 (including)8.0.0-alpha4 (including)
DrupalDrupal8.0.0-alpha5 (including)8.0.0-alpha5 (including)
DrupalDrupal8.0.0-alpha6 (including)8.0.0-alpha6 (including)
DrupalDrupal8.0.0-alpha7 (including)8.0.0-alpha7 (including)
DrupalDrupal8.0.0-alpha8 (including)8.0.0-alpha8 (including)
DrupalDrupal8.0.0-alpha9 (including)8.0.0-alpha9 (including)
DrupalDrupal8.0.0-beta1 (including)8.0.0-beta1 (including)
DrupalDrupal8.0.0-beta10 (including)8.0.0-beta10 (including)
DrupalDrupal8.0.0-beta11 (including)8.0.0-beta11 (including)
DrupalDrupal8.0.0-beta12 (including)8.0.0-beta12 (including)
DrupalDrupal8.0.0-beta13 (including)8.0.0-beta13 (including)
DrupalDrupal8.0.0-beta14 (including)8.0.0-beta14 (including)
DrupalDrupal8.0.0-beta15 (including)8.0.0-beta15 (including)
DrupalDrupal8.0.0-beta16 (including)8.0.0-beta16 (including)
DrupalDrupal8.0.0-beta2 (including)8.0.0-beta2 (including)
DrupalDrupal8.0.0-beta3 (including)8.0.0-beta3 (including)
DrupalDrupal8.0.0-beta4 (including)8.0.0-beta4 (including)
DrupalDrupal8.0.0-beta6 (including)8.0.0-beta6 (including)
DrupalDrupal8.0.0-beta7 (including)8.0.0-beta7 (including)
DrupalDrupal8.0.0-beta9 (including)8.0.0-beta9 (including)
DrupalDrupal8.0.0-rc1 (including)8.0.0-rc1 (including)
DrupalDrupal8.0.0-rc2 (including)8.0.0-rc2 (including)
DrupalDrupal8.0.0-rc3 (including)8.0.0-rc3 (including)
DrupalDrupal8.0.0-rc4 (including)8.0.0-rc4 (including)
DrupalDrupal8.0.1 (including)8.0.1 (including)
DrupalDrupal8.0.2 (including)8.0.2 (including)
DrupalDrupal8.0.3 (including)8.0.3 (including)
Drupal6Ubuntuprecise*
Drupal6Ubuntuupstream*
Drupal7Ubuntuartful*
Drupal7Ubuntuesm-infra-legacy/trusty*
Drupal7Ubuntuprecise*
Drupal7Ubuntutrusty*
Drupal7Ubuntutrusty/esm*
Drupal7Ubuntuupstream*
Drupal7Ubuntuwily*
Drupal7Ubuntuyakkety*
Drupal7Ubuntuzesty*

References