Title: Google Search Appliance proxystylesheet File Existence Verification
Info
Disclosure
Nov 21, 2005
Discovery
Jun 10, 2005
Dates
Exploit
Nov 21, 2005
Solution
Unknown
Description
The Google Search Appliance contains a flaw that allows a remote attacker to verify the existance of a file. The issue is due to the proxystylesheet parameter in the search request, which doesn't check for a directory traversal in the file name. This allows an attacker to prepend a ../ sequence to an absolute file path and verify its existance based on the error message returned.
Classification
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
OSVDB:
Web Related
Solution
Upgrade to the version specified by Google advisory GA-2005-08-m, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.