11/28/2005

Google Search API Cross Site Scripting Vulnerability

Filed under: — By Aviran Mordo @ 1:01 pm

A vulnerability has been identified in Google API Search Engine Script, which may be exploited by attackers to inject malicious HTML code. This flaw is due to an input validation error in the search module when processing a specially crafted “REQ” parameter, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user’s browser in the security context of an affected Web site.

French Security Incident Response Team (FrSIRT) rates this vulnerability as low and currently there is no solution to this flaw untill Google fixes the problem.

 

Leave a Reply

You must have Javascript enabled in order to submit comments.

All fields are optional (except comment).
Some comments may be held for moderation (depends on spam filter) and not show up immediately.
Links will automatically get rel="nofollow" attribute to deter spammers.

Powered by WordPress