Vulnerable Systems:
* Drupal 4.6.x versions before Drupal 4.6.10.
* Drupal 4.7.x versions before Drupal 4.7.4.
A malicious user may entice users to visit a specially crafted URL that may result in the redirection of Drupal form submission to a third-party site. A user visiting the user registration page via such a url, for example, will submit all data, such as his/her e-mail address, but also possible private profile data, to a third-party site.
Vendor Status:
Drupal issued an update for this vulnerability