The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses the history API.
References
Link | Resource |
---|---|
http://browser-shredders.blogspot.com/2014/01/cve-2014-1449-maxthon-cloud-browser-for.html | Exploit |
http://www.maxthon.com/android/changelog/ | Vendor Advisory |
Configurations
Information
Published : 2014-12-25 13:59
Updated : 2014-12-29 09:50
NVD link : CVE-2014-1449
Mitre link : CVE-2014-1449
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
maxthon
- maxthon_cloud_browser