|
Google Search Appliance ProxyStyleSheet Multiple Remote Vulnerabilities
The Google Search Appliance 'proxystylesheet' feature is susceptible to multiple remote vulnerabilities. These issues are due to a failure of the devices to securely implement user-specified XSLT style sheets when displaying search results. These flaws allow attackers to execute cross-site scripting, information disclosure, and remote command-execution attacks against the users of affected devices or against the devices themselves. Attackers may leverage the cross-site scripting issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks. Attackers may leverage the information-disclosure issues to determine the existence of arbitrary files on the targeted computer or to port-scan networks that are accessible to affected devices. This may aid attackers in further attacks. Attackers may leverage the command-execution vulnerability to execute arbitrary commands as an unprivileged user. The Google Mini Search Appliance is confirmed vulnerable to these issues. The Google Search Appliance may also be affected. |
|
|
Privacy Statement |