Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts via URLs with modified targets and ports, then comparing the resulting error messages to determine open and closed ports.
Link | Tags |
---|---|
http://secunia.com/advisories/17644 | third party advisory vendor advisory |
http://www.osvdb.org/20979 | exploit vdb entry patch |
http://metasploit.com/research/vulns/google_proxystylesheet/ | patch vendor advisory |
http://www.securityfocus.com/archive/1/417310/30/0/threaded | mailing list |
http://www.vupen.com/english/advisories/2005/2500 | vdb entry |
http://www.securityfocus.com/bid/15509 | vdb entry patch |
http://securitytracker.com/id?1015246 | vdb entry patch vendor advisory |