AplusWebMaster
Topic Starter
FYI…
- http://www.us-cert.gov/current/#flash_auth…rate_vulnerable
January 2, 2008 - "US-CERT is aware of reported vulnerabilities in Flash (SWF) files that may allow a remote, unauthenticated attacker to conduct cross-site scripting attacks on a vulnerable system. The flaws exist in the way that input is validated when passed to embedded ActionsScript and JavaScript in the SWF file. Authoring tools that automatically generate Flash files may introduce these vulnerabilities.
More information regarding these vulnerabilities can be found in:
> Vulnerability Note VU#249337 - http://www.kb.cert.org/vuls/id/249337
> Web site document "XSS Vulnerabilities in Common Shockwave Flash Files"
http://docs.google.com/View?docid=ajfxntc4dmsq_14dt57ssdw

- http://www.us-cert.gov/current/#flash_auth…rate_vulnerable
January 2, 2008 - "US-CERT is aware of reported vulnerabilities in Flash (SWF) files that may allow a remote, unauthenticated attacker to conduct cross-site scripting attacks on a vulnerable system. The flaws exist in the way that input is validated when passed to embedded ActionsScript and JavaScript in the SWF file. Authoring tools that automatically generate Flash files may introduce these vulnerabilities.
More information regarding these vulnerabilities can be found in:
> Vulnerability Note VU#249337 - http://www.kb.cert.org/vuls/id/249337
> Web site document "XSS Vulnerabilities in Common Shockwave Flash Files"
http://docs.google.com/View?docid=ajfxntc4dmsq_14dt57ssdw