Web Hack List

Other nomination

The old is new, again. CVE20112461 is back!

SWF files built with a pre-patch Adobe Flex SDK stay exploitable after the SDK is fixed, because the vulnerable localization code is compiled into the file. A crafted request parameter makes such a SWF run attacker JavaScript in the hosting site's origin, giving same-origin XSS and session or CSRF-token theft; the ParrotNG tool locates affected SWFs at scale.

Record

Researcher
Luca Carettoni and Mauro Gentile
Published by
troopers.de
Date
Format
Recording

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Luca Carettoni and Mauro Gentile, first published at the original source. Preserved copies are kept so the citation survives its host.