Drupal · Drupal Cck · CVE-2015-5510
**Name of the Vulnerable Software and Affected Versions**
Drupal CCK versions 6.x-2.x before 6.x-2.10
**Description**
The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the `destinations` parameter, related to administration pages.
**Recommendations**
For versions prior to 6.x-2.10, update to version 6.x-2.10 or later to resolve the issue. As a temporary workaround, consider restricting access to administration pages to minimize the risk of exploitation. Avoid using the `destinations` parameter in affected pages until the issue is resolved.