Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Maxthon Web Browser Plug-in API Directory Traversal Vulnerability

It is reported that the Maxthon Web browser Plug-ins employ 'readFile()' and 'writeFile()' API calls to access files in the Plug-in installation directory. However, reports indicate that it is possible to invoke these API calls to read and write arbitrary files by supplying directory traversal sequences in the path to a target file.

A remote attacker may exploit this issue to read and write files on a target computer with the privileges of a user that is running the vulnerable Web browser.







 

Privacy Statement
Copyright 2008, SecurityFocus