The current path could be populated with an external URL. This could lead to open redirect vulnerabilities.

This vulnerability is mitigated by the fact that it would only occur in combination with custom code, or in certain cases if a user submits a form shown on a 404 page with a specially crafted URL.

For Drupal 6, this patch also solves: Open redirect via double-encoded ‘destination’ parameter

The drupal_goto() function in Drupal 6 improperly decodes the contents of $_REQUEST[‘destination’] before using it, which allows the function’s open redirect protection to be bypassed and allows an attacker to initiate a redirect to an arbitrary external URL.

This vulnerability is mitigated by that fact that the attack is not possible for sites running on PHP 5.4.7 or greater.

Part of security release SA-CORE-2016-001

This vulnerability affects the following application versions:

  • Drupal 6.0
  • Drupal 6.1
  • Drupal 6.2
  • Drupal 6.3
  • Drupal 6.4
  • Drupal 6.5
  • Drupal 6.6
  • Drupal 6.7
  • Drupal 6.8
  • Drupal 6.9
  • Drupal 6.10
  • Drupal 6.11
  • Drupal 6.12
  • Drupal 6.13
  • Drupal 6.14
  • Drupal 6.15
  • Drupal 6.16
  • Drupal 6.17
  • Drupal 6.18
  • Drupal 6.19
  • Drupal 6.20
  • Drupal 6.21
  • Drupal 6.22
  • Drupal 6.23
  • Drupal 6.24
  • Drupal 6.25
  • Drupal 6.26
  • Drupal 6.27
  • Drupal 6.28
  • Drupal 6.29
  • Drupal 6.30
  • Drupal 6.31
  • Drupal 6.32
  • Drupal 6.33
  • Drupal 6.34
  • Drupal 6.35
  • Drupal 6.36
  • Drupal 6.37
  • Drupal 7.0
  • Drupal 7.1
  • Drupal 7.2
  • Drupal 7.3
  • Drupal 7.4
  • Drupal 7.5
  • Drupal 7.6
  • Drupal 7.7
  • Drupal 7.8
  • Drupal 7.9
  • Drupal 7.10
  • Drupal 7.11
  • Drupal 7.12
  • Drupal 7.13
  • Drupal 7.14
  • Drupal 7.15
  • Drupal 7.16
  • Drupal 7.17
  • Drupal 7.18
  • Drupal 7.19
  • Drupal 7.20
  • Drupal 7.21
  • Drupal 7.22
  • Drupal 7.23
  • Drupal 7.24
  • Drupal 7.25
  • Drupal 7.26
  • Drupal 7.27
  • Drupal 7.28
  • Drupal 7.29
  • Drupal 7.30
  • Drupal 7.31
  • Drupal 7.32
  • Drupal 7.33
  • Drupal 7.34
  • Drupal 7.35
  • Drupal 7.36
  • Drupal 7.37
  • Drupal 7.38
  • Drupal 7.39
  • Drupal 7.40
  • Drupal 7.41
  • Drupal 7.42
  • Drupal 8.0.0
  • Drupal 8.0.1
  • Drupal 8.0.2
  • Drupal 8.0.3

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *