Описание
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.
Ссылки
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Mailing ListPatchVDB Entry
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Mailing ListPatchVDB Entry
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
6.1 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
Связанные уязвимости
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.
Open redirect vulnerability in URL-related API functions in Drupal 6.x ...
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.
EPSS
6.1 Medium
CVSS3
5.8 Medium
CVSS2