Title: Maxthon Browser max.src Plug-in Security ID Generation File Manipulation
Info
Disclosure
Apr 08, 2005
Discovery
Mar 27, 2005
Dates
Exploit
Apr 08, 2005
Solution
Unknown
Description
Maxthon Browser contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the max.src file, which contains the "security id" for a plugin, is included in a script on a web page. API funtions can be called using the "security id" retrieved, allowing an attacker to call functions that will read and write to local files, which results in a loss of confidentiality and integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Public
Disclosure:
OSVDB Verified
Solution
Upgrade to version 1.2.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.