CVE Vulnerabilities

CVE-2016-3164

Published: Apr 12, 2016 | Modified: Apr 13, 2016
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.

Affected Software

Name Vendor Start Version End Version
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 6.0 6.0
Drupal Drupal 6.33 6.33
Drupal Drupal 7.40 7.40
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 7.16 7.16
Drupal Drupal 6.0 6.0
Drupal Drupal 7.21 7.21
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 6.2 6.2
Drupal Drupal 7.0 7.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 7.18 7.18
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 7.15 7.15
Drupal Drupal 7.0 7.0
Drupal Drupal 6.14 6.14
Drupal Drupal 7.38 7.38
Drupal Drupal 6.24 6.24
Drupal Drupal 6.13 6.13
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 6.0 6.0
Drupal Drupal 6.25 6.25
Drupal Drupal 6.18 6.18
Drupal Drupal 7.41 7.41
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 7.0 7.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 6.0 6.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 7.3 7.3
Drupal Drupal 6.12 6.12
Drupal Drupal 6.32 6.32
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 7.17 7.17
Drupal Drupal 7.8 7.8
Drupal Drupal 7.0 7.0
Drupal Drupal 7.13 7.13
Drupal Drupal 7.35 7.35
Drupal Drupal 6.0 6.0
Drupal Drupal 7.20 7.20
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 6.0 6.0
Drupal Drupal 6.4 6.4
Drupal Drupal 7.5 7.5
Drupal Drupal 6.11 6.11
Drupal Drupal 7.10 7.10
Drupal Drupal 7.30 7.30
Drupal Drupal 7.27 7.27
Drupal Drupal 7.6 7.6
Drupal Drupal 7.12 7.12
Drupal Drupal 6.0 6.0
Drupal Drupal 7.34 7.34
Drupal Drupal 6.36 6.36
Drupal Drupal 7.9 7.9
Drupal Drupal 7.0 7.0
Drupal Drupal 6.35 6.35
Drupal Drupal 6.26 6.26
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 7.0 7.0
Drupal Drupal 6.30 6.30
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 7.4 7.4
Drupal Drupal 7.x-dev 7.x-dev
Drupal Drupal 6.7 6.7
Drupal Drupal 8.0.2 8.0.2
Drupal Drupal 8.0.3 8.0.3
Drupal Drupal 7.28 7.28
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 7.22 7.22
Drupal Drupal 6.22 6.22
Drupal Drupal 7.0 7.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 6.8 6.8
Drupal Drupal 6.27 6.27
Drupal Drupal 6.19 6.19
Drupal Drupal 7.11 7.11
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 7.33 7.33
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 6.1 6.1
Drupal Drupal 6.28 6.28
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 6.21 6.21
Drupal Drupal 7.0 7.0
Drupal Drupal 7.19 7.19
Drupal Drupal 6.17 6.17
Drupal Drupal 6.5 6.5
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 7.25 7.25
Drupal Drupal 7.0 7.0
Drupal Drupal 7.32 7.32
Drupal Drupal 7.24 7.24
Drupal Drupal 6.31 6.31
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 6.10 6.10
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 7.14 7.14
Drupal Drupal 7.23 7.23
Drupal Drupal 8.0.1 8.0.1
Drupal Drupal 7.26 7.26
Drupal Drupal 7.0 7.0
Drupal Drupal 6.23 6.23
Drupal Drupal 6.6 6.6
Drupal Drupal 7.29 7.29
Drupal Drupal 6.0 6.0
Drupal Drupal 7.1 7.1
Drupal Drupal 7.31 7.31
Drupal Drupal 6.15 6.15
Drupal Drupal 6.0 6.0
Drupal Drupal 6.16 6.16
Drupal Drupal 7.7 7.7
Drupal Drupal 6.34 6.34
Drupal Drupal 7.0 7.0
Drupal Drupal 6.3 6.3
Drupal Drupal 7.2 7.2
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 6.0 6.0
Drupal Drupal 6.29 6.29
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 7.37 7.37
Drupal Drupal 7.42 7.42
Drupal Drupal 6.37 6.37
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 6.20 6.20
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 8.0.0 8.0.0
Drupal Drupal 7.36 7.36
Drupal Drupal 6.9 6.9

References