Index: includes/common.inc
===================================================================
RCS file: /cvs/drupal/drupal/includes/common.inc,v
retrieving revision 1.1175
diff -u -p -r1.1175 common.inc
--- includes/common.inc	5 Jun 2010 13:18:09 -0000	1.1175
+++ includes/common.inc	6 Jun 2010 19:38:25 -0000
@@ -659,7 +659,8 @@ function drupal_encode_path($path) {
  */
 function drupal_goto($path = '', array $options = array(), $http_response_code = 302) {
   // A destination in $_GET always overrides the function arguments.
-  if (isset($_GET['destination'])) {
+  // We do not allow absolute URLs to be passed via $_GET, as this can be an attack vector.
+  if (isset($_GET['destination']) && !url_is_external($_GET['destination'])) {
     $destination = drupal_parse_url($_GET['destination']);
     $path = $destination['path'];
     $options['query'] = $destination['query'];
Index: modules/simpletest/tests/common.test
===================================================================
RCS file: /cvs/drupal/drupal/modules/simpletest/tests/common.test,v
retrieving revision 1.112
diff -u -p -r1.112 common.test
--- modules/simpletest/tests/common.test	18 May 2010 06:59:46 -0000	1.112
+++ modules/simpletest/tests/common.test	6 Jun 2010 19:38:30 -0000
@@ -196,8 +196,13 @@ class CommonURLUnitTest extends DrupalWe
     );
     $this->assertEqual(drupal_parse_url($url), $result, t('Absolute URL parsed correctly.'));
 
-    // External URL.
+    // External URL testing.
     $url = 'http://drupal.org/foo/bar?foo=bar&bar=baz&baz#foo';
+
+    // Test that drupal can recognize an absolute URL. Used to prevent attack vectors.
+    $this->assertTrue(url_is_external($url), t('Correctly identified an external URL.'));
+
+    // Test the parsing of absolute URLs.
     $result = array(
       'path' => 'http://drupal.org/foo/bar',
       'query' => array('foo' => 'bar', 'bar' => 'baz', 'baz' => ''),
@@ -222,8 +227,12 @@ class CommonURLUnitTest extends DrupalWe
     // Non-clean URLs #3: URL generated by url() on non-Apache webserver.
     $url = 'index.php?q=foo/bar&bar=baz#foo';
     $this->assertEqual(drupal_parse_url($url), $result, t('Relative URL on non-Apache webserver with clean URLs disabled parsed correctly.'));
-  }
 
+    // Test that drupal_parse_url() does not allow spoofing a URL to force a malicious redirect.
+    $parts = drupal_parse_url('forged:http://cwe.mitre.org/data/definitions/601.html');
+    $this->assertFalse(valid_url($parts['path'], TRUE), t('drupal_parse_url() correctly parsed a forged URL.'));
+  }
+  
   /**
    * Test url() with/without query, with/without fragment, absolute on/off and
    * assert all that works when clean URLs are on and off.
