Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts via URLs with modified targets and ports, then comparing the resulting error messages to determine open and closed ports.
References
Link | Resource |
---|---|
http://metasploit.com/research/vulns/google_proxystylesheet/ | Patch Vendor Advisory |
http://secunia.com/advisories/17644 | Vendor Advisory |
http://securitytracker.com/id?1015246 | Patch Vendor Advisory |
http://www.osvdb.org/20979 | Exploit Patch |
http://www.securityfocus.com/archive/1/417310/30/0/threaded | |
http://www.securityfocus.com/bid/15509 | Patch |
http://www.vupen.com/english/advisories/2005/2500 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2005-11-22 21:03
Updated : 2018-10-19 15:39
NVD link : CVE-2005-3756
Mitre link : CVE-2005-3756
CVE.ORG link : CVE-2005-3756
JSON object : View
Products Affected
- search_appliance
- mini_search_appliance
CWE