First published: Sat Dec 02 2006(Updated: )
Cross-site scripting (XSS) vulnerability in Google Search Appliance and Google Mini allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded q parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Mini Search Appliance | ||
Google Search Appliance |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6223 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2006-6223, update to the latest version of Google Search Appliance or Google Mini that patches this vulnerability.
CVE-2006-6223 affects both Google Mini Search Appliance and Google Search Appliance.
CVE-2006-6223 is a cross-site scripting (XSS) vulnerability allowing remote attackers to inject malicious scripts.
Yes, CVE-2006-6223 can impact user data by allowing attackers to execute arbitrary web scripts in the context of users accessing the affected applications.