Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3167

Опубликовано: 12 апр. 2016
Источник: debian
EPSS Низкий

Описание

Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
drupal7not-affectedpackage
drupal6removedpackage
drupal6end-of-lifesqueezepackage

Примечания

  • https://www.drupal.org/SA-CORE-2016-001

  • https://www.openwall.com/lists/oss-security/2016/02/24/19

EPSS

Процентиль: 69%
0.00632
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 9 лет назад

Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.

CVSS3: 7.4
nvd
около 9 лет назад

Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.

CVSS3: 7.4
github
около 3 лет назад

Drupal Open redirect vulnerability in the drupal_goto function

EPSS

Процентиль: 69%
0.00632
Низкий