7.4

CVE-2016-3167

Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DrupalDrupal Version6.0 Updatebeta2
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.0 Updatebeta3
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.0 Updatebeta4
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.0 Updatedev
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.0 Updaterc1
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.0 Updaterc2
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.0 Updaterc3
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.0 Updaterc4
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.1
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.2
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.3
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.4
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.5
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.6
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.7
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.8
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.9
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.10
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.11
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.12
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.13
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.14
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.15
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.16
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.17
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.18
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.19
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.20
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.21
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.22
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.23
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.24
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.25
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.26
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.27
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.28
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.29
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.30
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.31
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.32
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.33
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.34
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.35
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.36
   PhpPhp Version <= 5.4.6
DrupalDrupal Version6.37
   PhpPhp Version <= 5.4.6
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.696
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.4 2.8 4
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N