CVE-2005-3754
Last modified
CVE-2005-3754 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via the proxystylesheet variable, which will be executed in the resulting error message.. EPSS estimates a 2.48% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via the proxystylesheet variable, which will be executed in the resulting error message.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mini Search Appliance | All versions | |
| Search Appliance | All versions |
References
- http://metasploit.com/research/vulns/google_proxystylesheet/Vendor Advisory
- http://secunia.com/advisories/17644Vendor Advisory
- http://securitytracker.com/id?1015246Exploit, Patch, Vendor Advisory
- http://metasploit.com/research/vulns/google_proxystylesheet/Vendor Advisory
- http://secunia.com/advisories/17644Vendor Advisory
- http://securitytracker.com/id?1015246Exploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3754?
How severe is CVE-2005-3754?
How do I fix CVE-2005-3754?
Are you affected by CVE-2005-3754?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
