First published: Tue Nov 22 2005(Updated: )
Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts via URLs with modified targets and ports, then comparing the resulting error messages to determine open and closed ports.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Mini Search Appliance | ||
Google Search Appliance |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3756 is rated as a medium severity vulnerability.
To mitigate CVE-2005-3756, restrict access to the Google Mini and Search Appliances to only trusted networks.
CVE-2005-3756 affects users of the Google Mini Search Appliance and potentially the Google Search Appliance.
CVE-2005-3756 allows attackers to perform remote port scanning through the Google Mini and Search Appliances.
Yes, if exploited, CVE-2005-3756 could allow attackers to identify open ports, potentially facilitating further attacks.