Full Disclosure mailing list archives

Maxthon browser search bar information disclosure advisory


From: "Aviv Raff" <avivra () gmail com>
Date: Fri, 25 Mar 2005 14:06:56 +0200


Maxthon browser search bar information disclosure advisory


URL: http://www.raffon.net/advisories/maxthon/searchbarid.html
Date: March 25, 2005
Author: Aviv Raff 


Introduction

"Maxthon Internet Browser software is a powerful tabbed browser with a
highly customizable interface. It is based on the Internet Explorer browser
engine..." (from Maxthon website <http://www.maxthon.com/> ).
Maxthon installs by default a search utility bar, which contains an
information disclosure vulnerability.


Technical Details

Maxthon's API includes a property named "m2_search_text", which allows
plug-ins to interact with the search bar.
Any website the user visits can easily fetch the search bar's data using
this property, the same way plug-ins do.
Tested version: 1.2.0
Older versions might be affected too. 


Proof Of Concept

http://www.raffon.net/advisories/maxthon/searchbarpoc.html



Timetable

02-Mar-2005: Vendor informed.
03-Mar-2005: Vendor confirmed vulnerability.
24-Mar-2005: Vendor published a fixed version.
25-Mar-2005: Public disclosure.



Solution

Upgrade to version 1.2.1.



Disclaimer: The information in this advisory and any of its demonstrations
is provided "as is" without warranty of any kind.

-- Copyright C 2005 Aviv Raff. --
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: