The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to obtain sensitive information and execute arbitrary code via dangerous Java class methods in select attribute of xsl:value-of tags in XSLT style sheets, such as (1) system-property, (2) sys:getProperty, and (3) run:exec.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2005-11-22T21:00:00
Updated: 2024-08-07T23:24:36.163Z
Reserved: 2005-11-22T00:00:00
Link: CVE-2005-3757
Vulnrichment
No data.
NVD
Status : Modified
Published: 2005-11-22T21:03:00.000
Modified: 2024-11-21T00:02:36.557
Link: CVE-2005-3757
Redhat
No data.