Security Advisory

CVE-2010-2021

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-06-25 21:00:00
Last updated 2024-08-07 02:17:13
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Open redirect vulnerability in the Global Redirect module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, when non-clean to clean is enabled, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter.