|
Maxthon Web Browser Plug-in API Security ID Information Disclosure Vulnerability
It is reported that the Maxthon Web browser is prone to an information disclosure vulnerability. It is reported that Maxthon Plug-in API's are protected with a security ID. Only a website that has knowledge of a Maxthon Plug-in security ID may invoke the plug-in API. However, it is reported that the Side bar Plug-in stores it's security ID in the Plug-in folder. It is possible for a remote website to include this file in a script and obtain the Security ID's required to access the API of the Plug-in. |
|
|
Privacy Statement |