Vulnerabilities > CVE-2009-3006 - Unspecified vulnerability in Maxthon Browser 2.5.3.80

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page.

Vulnerable Configurations

Part Description Count
Application
Maxthon
1

Oval

accepted2010-01-04T04:01:46.519-05:00
classvulnerability
contributors
nameSharath S
organizationSecPod Technologies
definition_extensions
commentMaxthon Browser is installed
ovaloval:org.mitre.oval:def:6262
descriptionMaxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page.
familywindows
idoval:org.mitre.oval:def:6437
statusaccepted
submitted2009-11-23T10:27:31.430-04:00
titleMaxthon Browser Address Bar Spoofing Vulnerability
version21