CVE-2005-3754

medium

Description

Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via the proxystylesheet variable, which will be executed in the resulting error message.

References

http://www.vupen.com/english/advisories/2005/2500

http://www.securityfocus.com/bid/15509

http://www.securityfocus.com/archive/1/417310/30/0/threaded

http://www.osvdb.org/20978

http://secunia.com/advisories/17644

http://metasploit.com/research/vulns/google_proxystylesheet/

Details

Source: Mitre, NVD

Published: 2005-11-22

Updated: 2018-10-19

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium