CVE-2007-5255
Google Mini Search Appliance 3.4.14 - Cross-Site Scripting via ie Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5255. PoCs published by Websecurity.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in Google Mini Search Appliance by injecting arbitrary script code via the 'ie' parameter in a crafted URL. The vulnerability allows execution of malicious scripts in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance 3.4.14 allows remote attackers to inject arbitrary web script or HTML via the ie parameter to the /search URI.
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in Google Mini Search Appliance by injecting arbitrary script code via the 'ie' parameter in a crafted URL. The vulnerability allows execution of malicious scripts in the context of the affected site.