First published: Wed Sep 27 2006(Updated: )
Google Mini 4.4.102.M.36 and earlier allows remote attackers to obtain sensitive information via a direct request for /search with an invalid client parameter, which reveals the path in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Mini Search Appliance | <=4.4.102.m.36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5019 has a critical severity rating due to the potential exposure of sensitive information.
The fix for CVE-2006-5019 involves upgrading the Google Mini Search Appliance to version 4.4.102.M.37 or later.
CVE-2006-5019 affects users of Google Mini Search Appliance versions 4.4.102.M.36 and earlier.
CVE-2006-5019 enables remote attackers to exploit the vulnerability to capture sensitive data through error messages.
Yes, CVE-2006-5019 is a remote vulnerability that can be exploited without physical access to the device.