CVE-2005-3756

high

Description

Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts via URLs with modified targets and ports, then comparing the resulting error messages to determine open and closed ports.

References

http://www.vupen.com/english/advisories/2005/2500

http://www.securityfocus.com/bid/15509

http://www.securityfocus.com/archive/1/417310/30/0/threaded

http://securitytracker.com/id?1015246

http://secunia.com/advisories/17644

http://metasploit.com/research/vulns/google_proxystylesheet/

Details

Source: Mitre, NVD

Published: 2005-11-22

Updated: 2018-10-19

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

Severity: High