Skip to main content
Participant
March 31, 2016
Question

What can be done about Flash allowing a URL parameter to point to an attacker's content?

  • March 31, 2016
  • 1 reply
  • 259 views

Our application uses Flash and one of the files allows a URL parameter to direct it to receive content. An attacker can exploit this by tricking a user into visiting a crafted URL making it look as though it’s our company’s content, but actually from the attacker.

Further attempts to exploit this, such as with cross-site flashing, failed as only content could be displayed, but no code was able to be executed.

This topic has been closed for replies.

1 reply

kglad
Community Expert
Community Expert
March 31, 2016

why is that url saved and used by another user?