Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via a proxystylesheet variable that contains a malicious XSLT style sheet.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-11-22 13:03
Updated : 2018-10-19 08:39
NVD link : CVE-2005-3758
Mitre link : CVE-2005-3758
JSON object : View
CWE
Products Affected
- search_appliance
- mini_search_appliance