Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts via URLs with modified targets and ports, then comparing the resulting error messages to determine open and closed ports.
References
Link | Resource |
---|---|
http://metasploit.com/research/vulns/google_proxystylesheet/ | Patch Vendor Advisory |
http://www.securityfocus.com/bid/15509 | Patch |
http://www.osvdb.org/20979 | Exploit Patch |
http://securitytracker.com/id?1015246 | Patch Vendor Advisory |
http://secunia.com/advisories/17644 | Vendor Advisory |
http://www.vupen.com/english/advisories/2005/2500 | |
http://www.securityfocus.com/archive/1/417310/30/0/threaded |
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-11-22 13:03
Updated : 2018-10-19 08:39
NVD link : CVE-2005-3756
Mitre link : CVE-2005-3756
JSON object : View
CWE
Products Affected
- search_appliance
- mini_search_appliance