The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses the history API.
References
Configurations
History
21 Nov 2024, 02:04
Type | Values Removed | Values Added |
---|---|---|
References | () http://browser-shredders.blogspot.com/2014/01/cve-2014-1449-maxthon-cloud-browser-for.html - Exploit | |
References | () http://www.maxthon.com/android/changelog/ - Vendor Advisory |
Information
Published : 2014-12-25 21:59
Updated : 2024-11-21 02:04
NVD link : CVE-2014-1449
Mitre link : CVE-2014-1449
CVE.ORG link : CVE-2014-1449
JSON object : View
Products Affected
maxthon
- maxthon_cloud_browser
CWE
CWE-284
Improper Access Control