Description
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
Remediation
References
Related Vulnerabilities
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9853)
WordPress Plugin Catch Sticky Menu Security Bypass (1.6.3)
WordPress Plugin WP-SpamFree Anti-Spam Cross-Site Scripting (2.1.1.6)
ZenCart Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-11675)