CVE Vulnerabilities

CVE-2016-3164

Published: Apr 12, 2016 | Modified: Apr 13, 2016
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.

Affected Software

Name Vendor Start Version End Version
Drupal Drupal 6.0 6.0
Drupal Drupal 6.0 6.0
Drupal Drupal 6.0 6.0
Drupal Drupal 6.0 6.0
Drupal Drupal 6.0 6.0
Drupal Drupal 6.0 6.0
Drupal Drupal 6.0 6.0
Drupal Drupal 6.0 6.0
Drupal Drupal 6.0 6.0
Drupal Drupal 6.0 6.0
Drupal Drupal 6.1 6.1
Drupal Drupal 6.2 6.2
Drupal Drupal 6.3 6.3
Drupal Drupal 6.4 6.4
Drupal Drupal 6.5 6.5
Drupal Drupal 6.6 6.6
Drupal Drupal 6.7 6.7
Drupal Drupal 6.8 6.8
Drupal Drupal 6.9 6.9
Drupal Drupal 6.10 6.10
Drupal Drupal 6.11 6.11
Drupal Drupal 6.12 6.12
Drupal Drupal 6.13 6.13
Drupal Drupal 6.14 6.14
Drupal Drupal 6.15 6.15
Drupal Drupal 6.16 6.16
Drupal Drupal 6.17 6.17
Drupal Drupal 6.18 6.18
Drupal Drupal 6.19 6.19
Drupal Drupal 6.20 6.20
Drupal Drupal 6.21 6.21
Drupal Drupal 6.22 6.22
Drupal Drupal 6.23 6.23
Drupal Drupal 6.24 6.24
Drupal Drupal 6.25 6.25
Drupal Drupal 6.26 6.26
Drupal Drupal 6.27 6.27
Drupal Drupal 6.28 6.28
Drupal Drupal 6.29 6.29
Drupal Drupal 6.30 6.30
Drupal Drupal 6.31 6.31
Drupal Drupal 6.32 6.32
Drupal Drupal 6.33 6.33
Drupal Drupal 6.34 6.34
Drupal Drupal 6.35 6.35
Drupal Drupal 6.36 6.36
Drupal Drupal 6.37 6.37
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.1 7.1
Drupal Drupal 7.2 7.2
Drupal Drupal 7.3 7.3
Drupal Drupal 7.4 7.4
Drupal Drupal 7.5 7.5
Drupal Drupal 7.6 7.6
Drupal Drupal 7.7 7.7
Drupal Drupal 7.8 7.8
Drupal Drupal 7.9 7.9
Drupal Drupal 7.10 7.10
Drupal Drupal 7.11 7.11
Drupal Drupal 7.12 7.12
Drupal Drupal 7.13 7.13
Drupal Drupal 7.14 7.14
Drupal Drupal 7.15 7.15
Drupal Drupal 7.16 7.16
Drupal Drupal 7.17 7.17
Drupal Drupal 7.18 7.18
Drupal Drupal 7.19 7.19
Drupal Drupal 7.20 7.20
Drupal Drupal 7.21 7.21
Drupal Drupal 7.22 7.22
Drupal Drupal 7.23 7.23
Drupal Drupal 7.24 7.24
Drupal Drupal 7.25 7.25
Drupal Drupal 7.26 7.26
Drupal Drupal 7.27 7.27
Drupal Drupal 7.28 7.28
Drupal Drupal 7.29 7.29
Drupal Drupal 7.30 7.30
Drupal Drupal 7.31 7.31
Drupal Drupal 7.32 7.32
Drupal Drupal 7.33 7.33
Drupal Drupal 7.34 7.34
Drupal Drupal 7.35 7.35
Drupal Drupal 7.36 7.36
Drupal Drupal 7.37 7.37
Drupal Drupal 7.38 7.38
Drupal Drupal 7.40 7.40
Drupal Drupal 7.41 7.41
Drupal Drupal 7.42 7.42
Drupal Drupal 7.x-dev 7.x-dev
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.1 8.0.1
Drupal Drupal 8.0.2 8.0.2
Drupal Drupal 8.0.3 8.0.3
Drupal6 Ubuntu precise *
Drupal6 Ubuntu upstream *
Drupal7 Ubuntu artful *
Drupal7 Ubuntu precise *
Drupal7 Ubuntu trusty *
Drupal7 Ubuntu upstream *
Drupal7 Ubuntu wily *
Drupal7 Ubuntu yakkety *
Drupal7 Ubuntu zesty *

References