Full Disclosure mailing list archives
Maxthon browser search bar information disclosure advisory
From: "Aviv Raff" <avivra () gmail com>
Date: Fri, 25 Mar 2005 14:06:56 +0200
Maxthon browser search bar information disclosure advisory URL: http://www.raffon.net/advisories/maxthon/searchbarid.html Date: March 25, 2005 Author: Aviv Raff Introduction "Maxthon Internet Browser software is a powerful tabbed browser with a highly customizable interface. It is based on the Internet Explorer browser engine..." (from Maxthon website <http://www.maxthon.com/> ). Maxthon installs by default a search utility bar, which contains an information disclosure vulnerability. Technical Details Maxthon's API includes a property named "m2_search_text", which allows plug-ins to interact with the search bar. Any website the user visits can easily fetch the search bar's data using this property, the same way plug-ins do. Tested version: 1.2.0 Older versions might be affected too. Proof Of Concept http://www.raffon.net/advisories/maxthon/searchbarpoc.html Timetable 02-Mar-2005: Vendor informed. 03-Mar-2005: Vendor confirmed vulnerability. 24-Mar-2005: Vendor published a fixed version. 25-Mar-2005: Public disclosure. Solution Upgrade to version 1.2.1. Disclaimer: The information in this advisory and any of its demonstrations is provided "as is" without warranty of any kind. -- Copyright C 2005 Aviv Raff. --
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Maxthon browser search bar information disclosure advisory Aviv Raff (Mar 25)