Vulnerabilities > CVE-2005-3756 - Remote vulnerability in Google Mini Search Appliance and Search Appliance

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
google
nessus

Summary

Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts via URLs with modified targets and ports, then comparing the resulting error messages to determine open and closed ports.

Vulnerable Configurations

Part Description Count
Hardware
Google
2

Nessus

NASL familyCGI abuses
NASL idGOOGLE_SEARCH_APPLIANCE_PROXYSTYLESHEET.NASL
descriptionThe remote Google Search Appliance / Mini Search Appliance fails to sanitize user-supplied input to the
last seen2020-06-01
modified2020-06-02
plugin id20241
published2005-11-22
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/20241
titleGoogle Search Appliance proxystylesheet Parameter Multiple Remote Vulnerabilities (XSS, Code Exec, ID)