This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Google Search Appliances vuln - workaround available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://secunia.com/advisories/23239/
Release Date: 2006-12-05
Critical: Less critical
Impact: Cross Site Scripting
Where: From remote
Solution Status: Unpatched
OS: Google Mini Search Appliance, Google Search Appliance
…The vulnerability is caused due to an error within the handling of UTF-7 encoded URIs. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Solution: Filter malicious characters and character sequences in a proxy…"

> http://en.wikipedia.org/wiki/Cross-site_scripting
"…Type of computer security vulnerability typically found in web applications which allow code injection by malicious web users into the web pages viewed by other users. Examples of such code include HTML code and client-side scripts…"

:ph34r:
Added:

> http://www.kb.cert.org/vuls/id/989144
"…Workaround
Google has provided workarounds for their customers.
* For Google Mini… https://support.google.com/enterprise/login…-2006-11-m.html
* For Google Search Appliance… https://support.google.com/enterprise/login…-2006-11-g.html
(require customer login)…"

- http://www.heise-security.co.uk/news/print/81676
"…Precisely this problem was reported about a year ago, at which time Google removed the flaw from its own website. Clearly they forgot to integrate the fixes into their own products…"

:ph34r: