Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3164

Опубликовано: 12 апр. 2016
Источник: debian
EPSS Низкий

Описание

Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
drupal8itppackage
drupal7fixed7.43-1package
drupal6removedpackage
drupal6end-of-lifesqueezepackage

Примечания

  • https://www.drupal.org/SA-CORE-2016-001

  • https://www.openwall.com/lists/oss-security/2016/02/24/19

EPSS

Процентиль: 70%
0.00663
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 9 лет назад

Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.

CVSS3: 7.4
nvd
около 9 лет назад

Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.

CVSS3: 7.4
github
около 3 лет назад

Drupal Open Redirect

EPSS

Процентиль: 70%
0.00663
Низкий