XMLWordPrintable

      It is possible to upload a flash swf file which when the attachment 'download' url is visited the flash swf file is executed in the browser and as such can use ExternalInterface.call() method to inject javascript defined in the swf file into the browser.

        1. CONF_25541.as
          0.4 kB
          David Black
        2. CONF_25541.swf
          0.6 kB
          David Black

              Unassigned Unassigned
              dblack David Black
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: