First published: Tue Nov 22 2005(Updated: )
Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via a proxystylesheet variable that contains a malicious XSLT style sheet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Mini Search Appliance | ||
Google Search Appliance |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3758 is classified as a medium severity vulnerability due to the potential for remote attackers to execute arbitrary scripts.
To mitigate CVE-2005-3758, ensure that your Google Mini Search Appliance or Google Search Appliance is updated to the latest firmware version provided by Google.
CVE-2005-3758 can lead to cross-site scripting (XSS) attacks, allowing attackers to inject malicious JavaScript into web pages viewed by users.
CVE-2005-3758 affects the Google Mini Search Appliance and potentially the Google Search Appliance.
Yes, CVE-2005-3758 can compromise users' data security by enabling attackers to manipulate web content maliciously.