PT-2009-5346 · Maxthon · Maxthon Browser

Lostmon

·

Published

2009-08-28

·

Updated

2017-09-19

·

CVE-2009-3006

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Maxthon Browser version 2.5.3.80 UNICODE
Description: The issue allows remote attackers to spoof the address bar. This can be achieved via window.open with a relative URI, showing an arbitrary URL on the web site visited by the victim. For example, a visit to an attacker-controlled web page can trigger a spoofed login form for the site containing that page.
Recommendations: For Maxthon Browser version 2.5.3.80 UNICODE, consider avoiding the use of window.open with relative URIs until a fix is available. As a temporary workaround, restrict access to potentially malicious web pages to minimize the risk of address bar spoofing.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-3006

Affected Products

Maxthon Browser