Top 10 winner
XSS Vulnerabilities in Common Shockwave Flash Files
Web authoring tools stamp the same vulnerable ActionScript into every SWF they generate, so hundreds of thousands of sites inherit XSS. Dreamweaver's skinName, Adobe Connect's baseurl, FusionCharts' dataURL, Camtasia's csPreloader and Autodemo's onend all pass attacker input to URL loaders, reachable through asfunction:getURL with a javascript: payload or by loading a remote SWF for cross-site flashing.
Record
- Researcher
- Rich Cannings
- Published by
- Google Docs
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Rich Cannings, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .