The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses the history API.
References
Link | Resource |
---|---|
http://browser-shredders.blogspot.com/2014/01/cve-2014-1449-maxthon-cloud-browser-for.html | Exploit |
http://www.maxthon.com/android/changelog/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2014-12-25 21:59
Updated : 2024-02-04 18:35
NVD link : CVE-2014-1449
Mitre link : CVE-2014-1449
CVE.ORG link : CVE-2014-1449
JSON object : View
Products Affected
maxthon
- maxthon_cloud_browser
CWE
CWE-284
Improper Access Control