CVE-2005-3758

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/11/2005
Last modified:
03/04/2025

Description

Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via a proxystylesheet variable that contains a malicious XSLT style sheet.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:google:mini_search_appliance:*:*:*:*:*:*:*:*
cpe:2.3:h:google:search_appliance:*:*:*:*:*:*:*:*