6.1

CVE-2015-7943

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3233.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Drupal ≫ Drupal Version 7.0
Drupal ≫ Drupal Version 7.0 Update alpha1
Drupal ≫ Drupal Version 7.0 Update alpha2
Drupal ≫ Drupal Version 7.0 Update alpha3
Drupal ≫ Drupal Version 7.0 Update alpha4
Drupal ≫ Drupal Version 7.0 Update alpha5
Drupal ≫ Drupal Version 7.0 Update alpha6
Drupal ≫ Drupal Version 7.0 Update alpha7
Drupal ≫ Drupal Version 7.0 Update beta1
Drupal ≫ Drupal Version 7.0 Update beta2
Drupal ≫ Drupal Version 7.0 Update beta3
Drupal ≫ Drupal Version 7.0 Update dev
Drupal ≫ Drupal Version 7.0 Update rc1
Drupal ≫ Drupal Version 7.0 Update rc2
Drupal ≫ Drupal Version 7.0 Update rc3
Drupal ≫ Drupal Version 7.0 Update rc4
Drupal ≫ Drupal Version 7.1
Drupal ≫ Drupal Version 7.2
Drupal ≫ Drupal Version 7.3
Drupal ≫ Drupal Version 7.4
Drupal ≫ Drupal Version 7.5
Drupal ≫ Drupal Version 7.6
Drupal ≫ Drupal Version 7.7
Drupal ≫ Drupal Version 7.8
Drupal ≫ Drupal Version 7.9
Drupal ≫ Drupal Version 7.10
Drupal ≫ Drupal Version 7.11
Drupal ≫ Drupal Version 7.12
Drupal ≫ Drupal Version 7.13
Drupal ≫ Drupal Version 7.14
Drupal ≫ Drupal Version 7.15
Drupal ≫ Drupal Version 7.16
Drupal ≫ Drupal Version 7.17
Drupal ≫ Drupal Version 7.18
Drupal ≫ Drupal Version 7.19
Drupal ≫ Drupal Version 7.20
Drupal ≫ Drupal Version 7.21
Drupal ≫ Drupal Version 7.22
Drupal ≫ Drupal Version 7.23
Drupal ≫ Drupal Version 7.24
Drupal ≫ Drupal Version 7.25
Drupal ≫ Drupal Version 7.26
Drupal ≫ Drupal Version 7.27
Drupal ≫ Drupal Version 7.28
Drupal ≫ Drupal Version 7.29
Drupal ≫ Drupal Version 7.30
Drupal ≫ Drupal Version 7.31
Drupal ≫ Drupal Version 7.32
Drupal ≫ Drupal Version 7.33
Drupal ≫ Drupal Version 7.34
Drupal ≫ Drupal Version 7.35
Drupal ≫ Drupal Version 7.36
Drupal ≫ Drupal Version 7.37
Drupal ≫ Drupal Version 7.38
Drupal ≫ Drupal Version 7.39
Drupal ≫ Drupal Version 7.40
Jquery Update Project ≫ Jquery Update Version 7.x-2.0 SwPlatform drupal
Jquery Update Project ≫ Jquery Update Version 7.x-2.1 SwPlatform drupal
Jquery Update Project ≫ Jquery Update Version 7.x-2.2 SwPlatform drupal
Jquery Update Project ≫ Jquery Update Version 7.x-2.3 SwPlatform drupal
Jquery Update Project ≫ Jquery Update Version 7.x-2.4 SwPlatform drupal
Jquery Update Project ≫ Jquery Update Version 7.x-2.5 SwPlatform drupal
Jquery Update Project ≫ Jquery Update Version 7.x-2.6 SwPlatform drupal
Labjs Project ≫ Labjs Version 7.x-1.0 SwPlatform drupal
Labjs Project ≫ Labjs Version 7.x-1.0 Update beta1 SwPlatform drupal
Labjs Project ≫ Labjs Version 7.x-1.0 Update rc1 SwPlatform drupal
Labjs Project ≫ Labjs Version 7.x-1.1 SwPlatform drupal
Labjs Project ≫ Labjs Version 7.x-1.2 SwPlatform drupal
Labjs Project ≫ Labjs Version 7.x-1.3 SwPlatform drupal
Labjs Project ≫ Labjs Version 7.x-1.4 SwPlatform drupal
Labjs Project ≫ Labjs Version 7.x-1.5 SwPlatform drupal
Labjs Project ≫ Labjs Version 7.x-1.6 SwPlatform drupal
Labjs Project ≫ Labjs Version 7.x-1.7 SwPlatform drupal
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.77% 0.753
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

http://www.debian.org/security/2017/dsa-3897
Third Party Advisory
http://www.securityfocus.com/bid/77293
Third Party Advisory
VDB Entry
https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2015-10-21/drupal-core-overlay-less-critical
Vendor Advisory
https://www.drupal.org/node/2598426
Vendor Advisory
https://www.drupal.org/node/2598434
Vendor Advisory