Collected research
Cross Context Scripting from within the Browser
malerisch.net: Maxthon - Cross Context Scripting (XCS) - about:history
Maxthon's about:history page renders visited-URL text unescaped, so a location.hash payload on any attacker page lands inside the privileged mx://res zone. From there the maxthon.io and maxthon.program DOM objects give file read and write and command execution; a Metasploit module overwrites j2plauncher.exe to get code running on Windows 7.
Record
- Document
- malerisch.net: Maxthon - Cross Context Scripting (XCS) - about:history
- Researcher
- Roberto Suggi Liverani
- Published by
- blog.malerisch.net
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Roberto Suggi Liverani, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .