Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destination URL.
http://www.securityfocus.com/bid/53365
http://www.mandriva.com/security/advisories?name=MDVSA-2013:074
http://secunia.com/advisories/49012
http://jvndb.jvn.jp/jvndb/JVNDB-2012-000045