Quantcast
Channel: Adobe Community: Message List - Flash Catalyst
Viewing all articles
Browse latest Browse all 180

What can be done about Flash allowing a URL parameter to point to an attacker's content?

$
0
0

Our application uses Flash and one of the files allows a URL parameter to direct it to receive content. An attacker can exploit this by tricking a user into visiting a crafted URL making it look as though it’s our company’s content, but actually from the attacker.

 

Further attempts to exploit this, such as with cross-site flashing, failed as only content could be displayed, but no code was able to be executed.


Viewing all articles
Browse latest Browse all 180

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>