AplusWebMaster
Topic Starter
FYI…
- http://secunia.com/advisories/23239/
Release Date: 2006-12-05
Critical: Less critical
Impact: Cross Site Scripting
Where: From remote
Solution Status: Unpatched
OS: Google Mini Search Appliance, Google Search Appliance
…The vulnerability is caused due to an error within the handling of UTF-7 encoded URIs. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Solution: Filter malicious characters and character sequences in a proxy…"
> http://en.wikipedia.org/wiki/Cross-site_scripting
"…Type of computer security vulnerability typically found in web applications which allow code injection by malicious web users into the web pages viewed by other users. Examples of such code include HTML code and client-side scripts…"

- http://secunia.com/advisories/23239/
Release Date: 2006-12-05
Critical: Less critical
Impact: Cross Site Scripting
Where: From remote
Solution Status: Unpatched
OS: Google Mini Search Appliance, Google Search Appliance
…The vulnerability is caused due to an error within the handling of UTF-7 encoded URIs. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Solution: Filter malicious characters and character sequences in a proxy…"
> http://en.wikipedia.org/wiki/Cross-site_scripting
"…Type of computer security vulnerability typically found in web applications which allow code injection by malicious web users into the web pages viewed by other users. Examples of such code include HTML code and client-side scripts…"