CVE-2016-3167 describes an open redirect vulnerability in the drupal_goto function of Drupal 6.x before version 6.38, specifically when used with PHP versions prior to 5.4.7. This flaw allows remote attackers to redirect users to arbitrary websites, facilitating phishing attacks through a double-encoded URL in the "destination" parameter. Rated with a CVSS score of 7.4 (High), the vulnerability requires user interaction (UI:R) but can lead to high integrity impact (I:H) with low attack complexity (AC:L) and no privileges required (PR:N). There is no evidence of active exploitation, no known exploit code available in Metasploit, Nuclei, or ExploitDB, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:6.0:beta2:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:6.0:beta3:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:6.0:beta4:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:6.0:dev:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:6.0:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.