CVE-2016-3164

HIGH

Drupal 6.x < 6.38, 7.x < 7.43, 8.x < 8.0.4 - Open Redirect via Path Manipulation

Title source: llm
STIX 2.1

Description

Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/02/24/19
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/03/15/10
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3498
Patch, Vendor Advisory x_refsource_confirm
https://www.drupal.org/SA-CORE-2016-001

Scores

CVSS v3 7.4
EPSS 0.0070
EPSS Percentile 72.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

Details

Status published
Products (41)
debian/debian_linux 7.0
debian/debian_linux 8.0
drupal/core 8.0 - 8.0.4Packagist
drupal/drupal 6.0 (10 CPE variants)
drupal/drupal 6.1
drupal/drupal 6.2
drupal/drupal 6.3
drupal/drupal 6.4
drupal/drupal 6.5
drupal/drupal 6.6
... and 31 more
Published Apr 12, 2016
Tracked Since Feb 18, 2026