Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors involving processing confirmation delete pages.
https://www.drupal.org/node/2454909
https://www.drupal.org/node/2454885
https://www.drupal.org/node/2454883
http://www.securityfocus.com/bid/73224