Cross-site scripting (XSS) vulnerability in Google Search Appliance and Google Mini allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded q parameter.
| Software | From | Fixed in |
|---|---|---|
| google / mini_search_appliance | - | - |
| google / search_appliance | - | - |