Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Maxthon Web Browser Plug-in API Security ID Information Disclosure Vulnerability

It is reported that the Maxthon Web browser is prone to an information disclosure vulnerability. It is reported that Maxthon Plug-in API's are protected with a security ID. Only a website that has knowledge of a Maxthon Plug-in security ID may invoke the plug-in API. However, it is reported that the Side bar
Plug-in stores it's security ID in the Plug-in folder.

It is possible for a remote website to include this file in a script and obtain the Security ID's required to access the API of the Plug-in.







 

Privacy Statement
Copyright 2008, SecurityFocus