|
Maxthon Web Browser Plug-in API Directory Traversal Vulnerability
It is reported that the Maxthon Web browser Plug-ins employ 'readFile()' and 'writeFile()' API calls to access files in the Plug-in installation directory. However, reports indicate that it is possible to invoke these API calls to read and write arbitrary files by supplying directory traversal sequences in the path to a target file. A remote attacker may exploit this issue to read and write files on a target computer with the privileges of a user that is running the vulnerable Web browser. |
|
|
Privacy Statement |