XMLWordPrintable

      It is possible to upload a flash swf file which when the attachment 'download' url is visited the flash swf file is executed in the browser and as such can use ExternalInterface.call() method to inject javascript defined in the swf file into the browser.

        1. CONF_25541.as
          0.4 kB
          David Black
        2. CONF_25541.swf
          0.6 kB
          David Black

            Unassigned Unassigned
            dblack David Black
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: