Release date: 2011-08-02
Updated on: 2011-08-02
Affected Systems:
Google Search Appliance 4.0
Unaffected system:
Google Search Appliance 5.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 48957
Cve id: CVE-2011-1339
Google Search Appliance is an all-in-one Search and indexing solution for small organizations and large organizations.
Google Search Appliance has a cross-site scripting vulnerability. Remote attackers can exploit this vulnerability to execute arbitrary code in the browsers of affected sites to steal Cookie authentication creden.
This vulnerability occurs when the application fails to properly filter user input for dynamic content generation.
<* Source: Yosuke Hasegawa
Link: http://jvn.jp/en/jp/JVN86220950/index.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Google
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.google.com