Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-2750

Опубликовано: 13 сент. 2017
Источник: debian
EPSS Низкий

Описание

Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
drupal7fixed7.32-1+deb8u2package
drupal6removedpackage
drupal6end-of-lifesqueezepackage

Примечания

  • https://www.drupal.org/SA-CORE-2015-001

  • http://cgit.drupalcode.org/drupal/commit/includes/menu.inc?h=6.x&id=8ffc5db3c0ab926f3d4b2cf8bc51714c8c0f3c93

  • http://cgit.drupalcode.org/drupal/commit/includes/common.inc?h=7.x&id=b44056d2f8e8c71d35c85ec5c2fb8f7c8a02d8a8

EPSS

Процентиль: 71%
0.00686
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 8 лет назад

Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.

CVSS3: 6.1
nvd
почти 8 лет назад

Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.

CVSS3: 6.1
github
около 3 лет назад

Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.

EPSS

Процентиль: 71%
0.00686
Низкий