Vulnerabilities > CVE-2007-1085 - Unspecified vulnerability in Google Desktop
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Cross-site scripting (XSS) vulnerability in Google Desktop allows remote attackers to bypass protection schemes and inject arbitrary web script or HTML, and possibly gain full access to the system, by using an XSS vulnerability in google.com to extract the signature for the internal web server, then calling the "under" parameter in Advanced Search with the proper signature.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Google Desktop Cross-Site Scripting Weakness. CVE-2007-1085. Webapps exploit for cgi platform |
id | EDB-ID:29623 |
last seen | 2016-02-03 |
modified | 2007-02-21 |
published | 2007-02-21 |
reporter | Yair Amit |
source | https://www.exploit-db.com/download/29623/ |
title | Google Desktop Cross-Site Scripting Weakness |
Nessus
NASL family | Windows |
NASL id | GOOGLE_DESKTOP_XSS_FLAW.NASL |
description | The version of Google Desktop installed on the remote host is affected by a cross-site scripting flaw because it fails to properly encode the output for the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 24710 |
published | 2007-02-26 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/24710 |
title | Google Desktop Advanced Search Internal Web Server XSS |
code |
|
References
- http://osvdb.org/33483
- http://securityreason.com/securityalert/2301
- http://www.kb.cert.org/vuls/id/615857
- http://www.securityfocus.com/archive/1/460735/100/0/threaded
- http://www.securityfocus.com/archive/1/460928/100/0/threaded
- http://www.securityfocus.com/bid/22650
- http://www.securitytracker.com/id?1017686
- http://www.watchfire.com/resources/Overtaking-Google-Desktop.pdf