Skip to main content
Participant
March 30, 2016
Question

Allowing a URL to direct to an attacker's content, is there a fix?

  • March 30, 2016
  • 1 reply
  • 632 views

Our application uses Flash and one of the files allows a URL parameter to direct it to receive content. An attacker can exploit this by tricking a user into visiting a crafted URL making it look as though it’s our company’s content, but actually from the attacker.

Further attempts to exploit this, such as with cross-site flashing, failed as only content could be displayed, but no code was able to be executed.

This topic has been closed for replies.

1 reply

Peter Grainge
Community Expert
Community Expert
March 30, 2016

Please click FlashHelp in the breadcrumbs above this thread and look at the Sticky topics. You will see that this forum is not the place for your question.

______________________________

Peter Grainge

www.grainge.org

Use the menu (bottom right) to mark the Best Answer or Highlight particularly useful replies. Found the answer elsewhere? Share it here.
Participant
March 30, 2016

New to this, so just delete.