Drupal could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in the drupal_goto() function. An attacker could exploit this vulnerability using the query string to redirect a victim to arbitrary Web sites.