Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Google Script Insertion Exploit Oct 19 2004 04:38PM
Jim Ley (jim jibbering com)


Website: www.google.com

Description: Google's custom websearch does not prevent javascript from

being inserted into the url of the image, allowing malicious users to modify

the content of the google page allowing in phishing attacks, or silently

steal search terms/results/clicks or modi...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus