ID

VAR-201507-0559


CVE

CVE-2014-9737


TITLE

Drupal for Language Switcher Dropdown Module open redirect vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2014-008094

DESCRIPTION

Open redirect vulnerability in the Language Switcher Dropdown module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a block. Supplementary information : CWE Vulnerability type by CWE-601: URL Redirection to Untrusted Site ( Open redirect ) Has been identified. http://cwe.mitre.org/data/definitions/601.htmlBy a third party URL Any user through Web You may be redirected to a site and run a phishing attack. An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. Other attacks are possible. Drupal is a free and open source content management system developed in PHP language maintained by the Drupal community

Trust: 1.98

sources: NVD: CVE-2014-9737 // JVNDB: JVNDB-2014-008094 // BID: 65078 // VULHUB: VHN-77682

AFFECTED PRODUCTS

vendor:language switcher dropdownmodel:language switcher dropdownscope:eqversion:7.x-1.1

Trust: 1.6

vendor:language switcher dropdownmodel:language switcher dropdownscope:eqversion:7.x-1.0

Trust: 1.6

vendor:language switcher dropdownmodel:language switcher dropdownscope:eqversion:7.x-1.2

Trust: 1.6

vendor:language switcher dropdownmodel:language switcher dropdownscope:eqversion:7.x-1.3

Trust: 1.6

vendor:language switcher dropdownmodel:language switcher dropdownscope:eqversion:7.x-1.4

Trust: 0.8

vendor:language switcher dropdownmodel:language switcher dropdownscope:ltversion:7.x-1.x

Trust: 0.8

sources: JVNDB: JVNDB-2014-008094 // CNNVD: CNNVD-201401-462 // NVD: CVE-2014-9737

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-9737
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-9737
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201401-462
value: MEDIUM

Trust: 0.6

VULHUB: VHN-77682
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-9737
severity: MEDIUM
baseScore: 5.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-77682
severity: MEDIUM
baseScore: 5.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-77682 // JVNDB: JVNDB-2014-008094 // CNNVD: CNNVD-201401-462 // NVD: CVE-2014-9737

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-Other

Trust: 0.8

sources: JVNDB: JVNDB-2014-008094 // NVD: CVE-2014-9737

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201401-462

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201401-462

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-008094

PATCH

title:lang_dropdown 7.x-1.4url:https://www.drupal.org/node/1614372

Trust: 0.8

title:DRUPAL-SA-CONTRIB-2014-006url:https://www.drupal.org/node/2179123

Trust: 0.8

sources: JVNDB: JVNDB-2014-008094

EXTERNAL IDS

db:NVDid:CVE-2014-9737

Trust: 2.8

db:OSVDBid:102382

Trust: 1.7

db:BIDid:65078

Trust: 1.0

db:JVNDBid:JVNDB-2014-008094

Trust: 0.8

db:CNNVDid:CNNVD-201401-462

Trust: 0.7

db:VULHUBid:VHN-77682

Trust: 0.1

sources: VULHUB: VHN-77682 // BID: 65078 // JVNDB: JVNDB-2014-008094 // CNNVD: CNNVD-201401-462 // NVD: CVE-2014-9737

REFERENCES

url:https://www.drupal.org/node/1614372

Trust: 1.7

url:https://www.drupal.org/node/2179123

Trust: 1.7

url:http://osvdb.org/102382

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-9737

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-9737

Trust: 0.8

url:http://www.securityfocus.com/bid/65078

Trust: 0.6

url:http://www.drupal.org

Trust: 0.3

sources: VULHUB: VHN-77682 // BID: 65078 // JVNDB: JVNDB-2014-008094 // CNNVD: CNNVD-201401-462 // NVD: CVE-2014-9737

CREDITS

Eric Peterson

Trust: 0.9

sources: BID: 65078 // CNNVD: CNNVD-201401-462

SOURCES

db:VULHUBid:VHN-77682
db:BIDid:65078
db:JVNDBid:JVNDB-2014-008094
db:CNNVDid:CNNVD-201401-462
db:NVDid:CVE-2014-9737

LAST UPDATE DATE

2025-04-13T23:09:48.133000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-77682date:2015-07-08T00:00:00
db:BIDid:65078date:2015-07-15T00:59:00
db:JVNDBid:JVNDB-2014-008094date:2015-07-10T00:00:00
db:CNNVDid:CNNVD-201401-462date:2015-07-07T00:00:00
db:NVDid:CVE-2014-9737date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-77682date:2015-07-06T00:00:00
db:BIDid:65078date:2014-01-22T00:00:00
db:JVNDBid:JVNDB-2014-008094date:2015-07-10T00:00:00
db:CNNVDid:CNNVD-201401-462date:2014-01-26T00:00:00
db:NVDid:CVE-2014-9737date:2015-07-06T15:59:02.073