网管联盟 | 网管论坛 | 网管u家 | 网管博客 | 网管软件 | 网管求职 | 小游戏 | 网管搜索 | 网管原创 | 网管聚合 | 网管读摘 | 网管焦点 | 世界素材 | 会员投稿 | 会员中心 
中国网管联盟
Windows Linux Cisco 网络技术 数据库 黑客攻防 DotNet Java PHP 认证 新闻资讯 服务器 存储资讯 网络设备 网管学堂 技术专题 焦点 网吧频道
 当前位置: > bitsCN.com > 网络攻防 > 黑客技术 > Exploit > Google Mini Search Appliance Input Validation Hole in 'ie' Parameter P  

Google Mini Search Appliance Input Validation Hole in 'ie' Parameter P

2007-10-13  作者:bitsCN整理  来源:中国网管联盟  点评 投稿 收藏

Impact:  Disclosure of authentication information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information
Fix Available:  Yes   Exploit Included:  Yes   Vendor Confirmed:  Yes 
Description:  A vulnerability was reported in Google Mini Search Appliance. A remote user can conduct cross-site scripting attacks.

网管朋友网www_bitscn_net

The device does not properly filter HTML code from user-supplied input in the 'ie' parameter before displaying the input. A remote user can create a specially crafted URL that, when loaded by a target user, will cause arbitrary scripting code to be executed by the target user's browser. The code will originate from the Google Mini Search Appliance device and will run in the security context of that device. As a result, the code will be able to access the target user's cookies (including authentication cookies), if any, associated with the device, access data recently submitted by the target user via web form to the device, or take actions on the device acting as the target user. 网管有家bitscn.net

A demonstration exploit URL is provided: 网管联盟bitsCN@com

http://[target]/search?ie=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
&site=x& output=xml_no_dtd'&client=x&proxystylesheet=x'

网管u家www.bitscn.net

The original advisory is available at:

网管联盟bitsCN@com

http://websecurity.com.ua/1368/
Impact:  A remote user can access the target user's cookies (including authentication cookies), if any, associated with the Google Mini Search Appliance device, access data recently submitted by the target user via web form to the device, or take actions on the device acting as the target user.
Solution:  The vendor has issued a fix.

网管下载dl.bitscn.com

The Google advisory is available at:

网管联盟bitsCN_com

https://support.google.com/enterprise/doc/mini/advisories/ga-2007-09-m.html
Vendor URL:  www.google.com/ (Links to External Site)
Cause:  Input validation error

网管u家bitscn.net

TAGs     the   user   target   device   The   code   of   to   access   will      
 上一篇:CyberLink PowerDVD Lets Remote Users Deny Service By Overwriting Files   下一篇:Xen NE2000 Driver Heap Overflow May Let Local Users Gain Elevated Privileges
Google Mini Search Appliance Input Validation Hole in 'ie' Parameter P 评论:
loading.. 评论加载中…
评论:请自觉遵守互联网相关政策法规,评论不得超过250字。

验证码: 注册用户
本类热门排行:
最新推荐文章:
网管论坛交流: