CVE Vulnerabilities

CVE-2016-3167

Published: Apr 12, 2016 | Modified: Apr 19, 2016
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the destination parameter.

Affected Software

Name Vendor Start Version End Version
Php Php * 5.4.6 (including)
Drupal6 Ubuntu precise *
Drupal6 Ubuntu upstream *

References