Description
Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.
Remediation
References
Related Vulnerabilities
MySQL CVE-2024-21069 Vulnerability (CVE-2024-21069)
phpMyAdmin Other Vulnerability (CVE-2007-0204)
WebLogic Improper Handling of Exceptional Conditions Vulnerability (CVE-2017-5638)
WordPress Plugin Custom Post Type UI Cross-Site Request Forgery (1.7.3)
WordPress Plugin Auctions 'upload.php' Arbitrary File Upload (2.0.1.3)