Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2016/02/24/19 | mailing list |
http://www.openwall.com/lists/oss-security/2016/03/15/10 | mailing list |
http://www.debian.org/security/2016/dsa-3498 | vendor advisory |
https://www.drupal.org/SA-CORE-2016-001 | patch vendor advisory |