5.8

CVE-2012-2727

Open redirect vulnerability in the Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when synchronizing user data, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bryce HamrickJanrain Capture Version6.x-1.0
   DrupalDrupal Version-
Bryce HamrickJanrain Capture Version7.x-1.0
   DrupalDrupal Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.35% 0.814
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:N/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.openwall.com/lists/oss-security/2012/06/14/3
http://drupal.org/node/1632702
Patch
http://drupal.org/node/1632704
Patch
http://drupal.org/node/1632734
Patch
Vendor Advisory
http://secunia.com/advisories/49480
Vendor Advisory
http://www.osvdb.org/82958
http://www.securityfocus.com/bid/53992
https://exchange.xforce.ibmcloud.com/vulnerabilities/76292