CVE-2005-3757
The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to obtain sensitive information and execute arbitrary code via dangerous Java class methods in select attribute of xsl:value-of tags in XSLT style sheets, such as (1) system-property, (2) sys:getProperty, and (3) run:exec.
Published
2005-11-22T21:03:00.000
Last Modified
2025-04-03T01:03:51.193
Status
Deferred
Source
[email protected]
Severity
CVSSv2: 7.5 (HIGH)
CVSSv2 Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
- Access Vector: NETWORK
- Access Complexity: LOW
- Authentication: NONE
- Confidentiality Impact: PARTIAL
- Integrity Impact: PARTIAL
- Availability Impact: PARTIAL
Exploitability Score
10.0
Impact Score
6.4
Weaknesses
-
Type: Primary
NVD-CWE-Other
Affected Vendors & Products
References
-
http://metasploit.com/research/vulns/google_proxystylesheet/
Exploit, Patch, Vendor Advisory
([email protected])
-
http://secunia.com/advisories/17644
Vendor Advisory
([email protected])
-
http://securitytracker.com/id?1015246
Exploit, Patch, Vendor Advisory
([email protected])
-
http://www.osvdb.org/20981
Exploit, Patch
([email protected])
-
http://www.securityfocus.com/archive/1/417310/30/0/threaded
([email protected])
-
http://www.securityfocus.com/bid/15509
Exploit, Patch
([email protected])
-
http://www.vupen.com/english/advisories/2005/2500
([email protected])
-
http://metasploit.com/research/vulns/google_proxystylesheet/
Exploit, Patch, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://secunia.com/advisories/17644
Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://securitytracker.com/id?1015246
Exploit, Patch, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.osvdb.org/20981
Exploit, Patch
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.securityfocus.com/archive/1/417310/30/0/threaded
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.securityfocus.com/bid/15509
Exploit, Patch
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.vupen.com/english/advisories/2005/2500
(af854a3a-2127-422b-91ae-364da2661108)